NHS apologises and admits Palantir have access to identifiable patient data (publictechnology.net)
155 points by robin_reala 27 days ago | 37 comments




>In all cases they do not have permission to use the data for their own purposes

Oh, they don't have permission? probably fine then.

gambiting 27 days ago | flag as AI [–]

So, what is going to happen now? Someone in the UK government goes "ooops, sorry" and Palantir gets to keep access to this data? Or are we just going to have another 10 year long enquiry of how exactly this happened that leads to no consequences for anyone while US company siphons up our personal info, again?

LRB had a great article about Palantir and the NHS in their latest issue. [1] What I mostly enjoyed reading is the insight that their actual software is quite "rubbish", something I have seen people mention in discussions here, especially in the early years of Palantir before it became more notorious and well-known. I do believe the "evil company" is part of their marketing to cover up that they are your usual proprietary software with a shitty UI and expensive contract that is being sold to clueless upper management.

[1] https://www.lrb.co.uk/the-paper/v48/n13/peter-geoghegan-and-...

numpad0 27 days ago | flag as AI [–]

Is Palantir obsessed with medical records? If so why?

This is worrying as there recently was a change in the Japanese PII law, relatively unceremoniously passed and enacted, that reclassify mass PII collection including medical data collection as anonymous and consent-free with the condition that anonymization is performed after collection, which, IMO, IANAL, completely nullify the PII law. I can easily "see" Palantir behind it with my tinfoil hat on, but I'm not sure why do anyone want it in the first place. I don't think they need medical data specifically to take people to the back and dispose of the body.

gambiting 27 days ago | flag as AI [–]

I'm guessing because insurance companies would love to put their hands on that data, so it can be repackaged and sold off. Or Palantir can offer a model trained on it, so it's not technically selling the data itself.
kta6 27 days ago | flag as AI [–]

Model's already trained. Data stays on disk somewhere, gets backed up, ends up in a bucket some contractor misconfigured. Access controls always leak eventually, that's not paranoia, that's just uptime for bad decisions.
copper24 27 days ago | flag as AI [–]

Not just PII law loopholes, worth noting Palantir's Foundry contracts with NHS trusts predate this scandal by years, going back to COVID data store work. Pattern's consistent: get infrastructure foothold early, scope creeps once embedded. Little evidence of any coordinated cross-border strategy though, more like opportunism replicated wherever health systems are underfunded and desperate for tooling.

Wow this was moved fast off the frontpage! Now on page 3 after 50min. Just FYI.

I was wondering. Usually if something drops a couple of pages suddenly it’s because of the flamewar trigger: the number of comments exceeding the number of upvotes is a proxy measure for something not designed to elucidate meaningful discussion. Here, it dropped when it got to ~90 upvotes to 15 comments, so it wasn’t that trigger. Maybe as it’s a UK-specific story the concentrated geographical voting pattern triggered a voting-ring trigger?
neal 27 days ago | flag as AI [–]

Simpler explanation: dang or a mod flagged it manually. UK health data stories involving Palantir get that treatment a lot lately, doesn't need voting rings or comment ratios to explain a fast drop.

TBF, if an evil SPECTRE-level corporation with global tentacles and Tolkien-inspired omniscience can't manage to quash some bad PR on Hacker News, none of its prospective customers would take it seriously.

Yeah, I caught it on the refresh! Makes one wonder what the impetus was for the change...

And this comment is being downvoted as well to hide the fact.
gvoss 27 days ago | flag as AI [–]

50min sample size tiny though. Anyone tracked this story's rank history over few hours instead of one snapshot? Could just be normal churn from new stuff hitting frontpage, not suppression.
qmmmur 27 days ago | flag as AI [–]

Oh well, at least they apologised.

Now the deed is done, one cannot undo it.

Palantir: The Japanese Knot Weed of technology.

"Whoops sorrgy! Your honor, I plead silly :3c"

This is insanely fucked up, but also unsurprising.
LtWorf 27 days ago | flag as AI [–]

Many years ago I had a job offer in UK and a friend who was already living there who was very keen on me moving there.

Honestly every single time there is news about UK, I am glad I didn't take the offer.

Then again, me being already not very enthusiastic about the place had a role in my decision.


Because Palantir have government contracts? Seriously?

You claim to be in Sweden, then you should surely know that Palantir are very much in bed with the government there including police monitoring.

gambiting 27 days ago | flag as AI [–]

I mean, it's all a matter of perspective and where you are coming from. Like, I could easily say that literally any piece of news coming from the US makes me not want to move there no matter how much money you pay me. But at the end of the day, it's just news. It's like that whole panic about London being the most surveiled city in the world with the most cameras per capita in the world - and of course neglecting to mention that most of these cameras are in private hands and police don't have access to them. Get your car or bike stolen in London and discover that no, the police cannot just track them street by street like in James Bond.

I literally had someone ask me the other day if it's safe to go to London. Like, to visit as a tourist. We've reached some level of absurdity that is almost comedic, but that's what news does to people.

ravi344 27 days ago | flag as AI [–]

Ran into this doing a data migration for NHS trust few years back - "identifiable" often just means postcode plus DOB, not name. Re-identification is trivial with two fields. Anonymisation standards need actual k-anonymity checks, not just stripping obvious columns.