英国国家医疗服务体系(NHS)为其数据保护披露不准确向公众道歉[1]。NHS之前发布的《数据保护影响评估》文件声称仅NHS员工可访问可识别患者信息[1],但这一表述被证实存在重大漏洞[1]。实际上,Palantir及其他供应商的员工通过联邦数据平台获得了这类敏感数据的访问权限[1]。
据披露,3名Palantir工程师拥有国家数据整合系统的管理员级访问权限,另有33名来自各供应商的工程师拥有受限的项目特定访问权[1]。国家数据卫士Dr Nicola Byrne就此向NHS提出了质询[1]。NHS随后澄清表示"我们一直在公开和网站上明确指出授权的供应商用户将被赋予数据访问权"[1]。
议会科学、创新和技术委员会对此事表达了严重关切,指出Palantir是公共部门"最令人担忧的例子",反映出政府对少数主要技术提供商过度依赖的问题[1]。该委员会建议政府在2027年3月前行使中止条款退出该合作[1]。
The UK's National Health Service has acknowledged inaccuracies in its Data Protection Impact Assessment, which previously claimed that only NHS staff could access identifiable patient information [1]. The health authority apologised after it became clear that employees from Palantir and other suppliers can in fact access sensitive patient data through the federated data platform [1].
According to the disclosure, three Palantir engineers hold administrator-level access to the national data integration system, while an additional 33 engineers from various suppliers possess restricted project-specific access rights [1]. National Data Guardian Dr Nicola Byrne raised concerns about these access arrangements with the NHS [1]. The health service responded by stating that it has "consistently been clear in public statements and on our website that authorised supplier users would be granted data access" [1].
The Parliamentary Science, Innovation and Technology Committee has recommended that the government exercise a break clause to exit the partnership by March 2027 [1]. The committee identified Palantir as a particularly concerning example of public sector over-reliance on a small number of major technology providers [1].