The NHS Apologized. But Your Medical Records Are Still Being Read by Palantir Engineers.

Your medical history is sitting on a server that engineers from a defense contractor can look at. Right now. The NHS just apologized for it. But nothing has changed.

Let’s be clear about what “apologized” means here. It means they admitted that Palantir engineers have access to identifiable patient data. It means they said sorry. It does not mean they turned off the access. It does not mean they changed the contract. It means they issued a statement, promised to tighten controls, and then went back to business as usual.

The apology is not a fix—it’s a PR bandage. The bleeding hasn’t stopped. Your data is still visible.

If you’ve ever been treated by the NHS, you have a stake in this. Your name, your diagnosis, your prescription history, your most private health details—they’re now part of a system that a private company can reach into. Not because of a hack. Because of a contract.

And here’s the part that should make your stomach drop: the official line is that engineers “do not have permission to use the data for their own purposes.” Oh, they don’t have permission? Great. But they can read it. They can see it. They can make copies in their heads. Permission is a rule, not a lock. And rules are only as good as the enforcement behind them.

This isn’t a bug. It’s a feature of how public procurement works now. The NHS—like many public institutions—has become structurally dependent on private contractors to run core services. The data sovereignty was already ceded the moment the contract was signed. The apology is just reputational maintenance.

Think about what that means. The same company that built the surveillance systems for the U.S. military and intelligence agencies now has eyes on your medical records. Not because they’re evil. Because we made it easy for them. We outsourced the backbone of public health to private interests, and now we’re surprised when they act like private interests.

You don’t need malicious intent when you have structural dependency. The data flows. The engineers read. The apology comes later. That’s the pattern.

So what can you do? Nothing directly. You can’t opt out. You can’t demand your records be removed from the system. The NHS holds your data, and it decides who gets to see it. Your consent was never really part of the equation.

But you can stop pretending this is a scandal. This is not a mistake. This is the logical endpoint of a procurement model that treats patient data as a resource to be extracted, not a trust to be protected. The apology is the cover, not the correction.

Every time you hear “they don’t have permission to use it,” remember: reading is using. Permission is a word. Access is a reality.

FAQ

Q: Does the fact that Palantir engineers 'don't have permission to use the data' mean they can't look at it?

A: No. Permission is a policy, not a technical barrier. They can read the data—they just aren't supposed to use it for their own purposes. That's a huge difference. Reading is a form of use, and once you've seen it, you can't unsee it.

Q: What practical impact does this apology have on my data?

A: None. The apology is about reputational damage control. The access remains. The contract remains. The system remains. Unless there is a fundamental change in procurement rules, your data is still accessible to Palantir engineers.

Q: Isn't this just an overreaction? Palantir is a legitimate company working with the NHS to improve healthcare.

A: That's the standard defense. But the core issue isn't Palantir's intentions—it's that your most sensitive data is now visible to a private third party without your explicit consent. Even if they're angels today, the structure allows any future misuse. The system is the problem, not the company.

📎 Source: View Source