The Company Helping ICE Deport People Now Has Access to Your Health Records

NHS England gave a U.S. surveillance contractor unlimited access to your identifiable health records. Here's who they handed it to, and what you can do about it.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Every time you see a doctor, you share information you wouldn't tell most people. Your diagnoses, your medications, your mental health…You share it because you have to, and because the National Health Service (NHS) has always felt like a safe place to do it.

This week, it got harder to feel that way.

NHS England has granted staff from a U.S. spy-tech company, Palantir Technologies, access to identifiable patient data before anonymization, according to a recently leaked document:

“The public will be rightfully concerned that data privacy is not the first concern,” Martin Wrigley, a Liberal Democrat of the House of Commons technology committee, said of the leaked note. “This somewhat cavalier attitude to data security demonstrated how this whole project does not have security by design at its heart.”

In this article
Palantir now granted full admin access to NHS England data
Who is Palantir?
Why this matters to you
What you can do
Bottom line

Palantir now granted full admin access to NHS England data

Palantir holds a £330 million contract to run a data-sharing system called the Federated Data Platform (FDP), which connects information from hospitals, general practitioner surgeries, and NHS organizations across England.

Under the previous 2023 contract, Palantir staff had to apply to access specific pseudonymized data sets. Now, certain staff get an "admin" role with, in the NHS's own words, "unlimited access" to patient data before it’s anonymized.

According to the Financial Times, the NHS says it has strict safeguards in place and that all external access requires government security clearance. But its own internal briefing note that was leaked acknowledged the change could create a "risk of loss of public confidence."

Who is Palantir?

Palantir is an American data company founded with backing from the CIA. It builds software that enables governments and agencies to search large volumes of data to identify patterns and targets.

Palantir has two main products: the Gotham and Foundry platforms. While they share the same underlying technology, Gotham is the platform used predominantly among intelligence agencies, while Foundry operates in civilian-facing organizations. Foundry is the platform currently used by the NHS — they call it the “Federated Data Platform” (FDP).

In the United States, Palantir has spent over a decade building surveillance tools for immigration enforcement:

Immigration enforcement isn’t the only thing Palantir is involved in. In April 2026, Palantir's CEO, Alexander C. Karp published a book, The Technological Republic, which they briefly summarized on X, calling for AI weapons and compulsory universal military service. Former employees wrote an open letter condemning the company's direction.

Why this matters to you

Your health records contain personal information you might not have told your closest family members. A mental health diagnosis. A sensitive test result. A prescription you'd rather keep private. When you share that information with the NHS, you're not consenting to it being accessible to a private U.S. company with defense contracts.

On top of that, nobody outside NHS England can independently verify whether the promises being made are being kept.

According to an investigation done by The Nerve’s Carole Cadwalladr, Palantir holds 34 contracts across at least 10 U.K government departments, including:

  1. Ministry of Defense
  2. Home Office
  3. Cabinet Office
  4. Department for Health & Social Care
  5. The Metropolitan Police
  6. Government Communications Headquarters
  7. Department for Levelling Up, Housing and Communities
  8. Highways England
  9. Defra

The tenth, of course, is the NHS itself.

That’s the same company, the same technology, increasingly woven into British public services, with very little public visibility into how it all connects.

In March 2026, nearly a third of FDP trusts using the platform were found to be failing basic data security standards.

What you can do

The honest answer? Not much.

The NHS made this decision without asking you, and there's no way to retroactively remove your records from a system you never opted into.

That said, there are a few things worth doing:

  • Register a National Data Opt-Out at nhs.uk. This limits how your records are used for purposes beyond your direct care. It won't touch what's already been shared, and it doesn't apply to everything, but it's the most direct lever you have.
  • Remove yourself from data broker databases. Companies like Palantir draw on profiles built from commercial data pipelines. Data removal services repeatedly contact brokers on your behalf to request that your information be removed.

Bottom line

You shared your health records with the NHS. The NHS (without telling you) gave Palantir, a U.S. defense contractor, access to them. That contractor has a long record of building government surveillance tools, and we only found out because someone leaked a document.

In a recent All About Cookies survey, 69% of people said they're concerned about how much data the government can access about them, while 60% said there's something in their digital footprint they don't want others to find.

Regardless of whether Palantir is doing anything wrong with your data, the situation raises a question worth sitting with: Who decided this was acceptable, and why didn't they think you needed to know?

Take Control of Your Online Privacy
5.0
Editorial Rating
Get Deal
On Incogni's website
2026 Editors’ Choice
Best Overall Data Removal Service
Privacy Protection
Incogni
EXCLUSIVE: Save 55% with code COOKIE
  • Top-rated data removal service that scrubs your info from 420+ data broker sites automatically
  • Independently verified by Deloitte, meaning removals are actually sent, confirmed, and not just claimed
  • The Unlimited plan extends coverage to 2,000+ additional sites with human-assisted custom removals