NHS England has admitted to an error in its Data Protection Impact Assessment (DPIA) concerning Palantir's access to patient data within the Federated Data Platform (FDP). The initial DPIA stated that identifiable patient information access would be limited to NHS staff, but it was later clarified that some external supplier staff, including those from Palantir, can access this data for specific technical purposes under NHS England's direction. Health Minister Preet Kaur Gill apologized for the error, attributing it to a mistake in the language used to describe access, rather than a change in actual access controls. She emphasized that safeguards are in place, access is audited and time-limited, and the NHS remains the data controller.

The National Data Guardian (NDG), Nicola Byrne, had requested clarification after media reports and subsequent confirmation indicated external contractors had access. Byrne highlighted that this error eroded public confidence, emphasizing the importance of transparency regarding who can access patient data. NHS England stated it is working with the NDG to implement recommendations and update the DPIA, affirming its commitment to strict data management policies and transparency.

Sam Smith, coordinator at medConfidential, criticized NHS England, suggesting the "typo" was a result of a "culture of fear" preventing expert staff from speaking up. The Federated Data Platform, powered by Palantir under a $330 million contract awarded in November 2023, is intended to monitor NHS performance and improve patient care. While a Palantir executive clarified that "unlimited access" referred to a specific technical permission in a staging environment, the controversy has underscored the need for clear and accurate communication about data access in critical health systems.