🌐 Orbit Publishing Network | Public Interest Audit Division
Home › Public Governance Notices › From CIA Targeting to NHS Wards: Palantir FDP Pipeline Audit
Palantir FDP Investigation • Part 01

From CIA Targeting to NHS Wards: What Is Palantir’s Military Tech Actually Doing With Your Medical File?

Inside the machine: How to trace your medical data through the Palantir FDP network and force your local Trust to reveal what they are extracting.

Platform: NHS Palantir Foundry FDP
Contract Value: £330 Million
Target Slug: palantir-nhs-surveillance-pipeline
Statutory Anchor: UK GDPR / DPA 2018

1. The Bed Management Mask vs. Military-Grade Analytics

If you follow official NHS England press releases, the £330 million Federated Data Platform (FDP) is presented as a routine hospital management tool. Ministers insist the software merely helps consultants schedule operating theatres, clear waiting lists, and manage bed occupancy across Integrated Care Boards (ICBs).

However, Palantir Technologies was not built in Silicon Valley to manage hospital beds. Founded with seed capital from the CIA’s venture arm (In-Q-Tel), Palantir developed its core software—Foundry and Gotham—to integrate fragmented intelligence feeds, track targets, and run predictive analytics for defense and intelligence agencies.

Deploying military-grade data integration software into the NHS requires a continuous, high-volume pipeline of raw personal health records. To run predictive scheduling and cross-trust bed mapping, Foundry does not look at aggregated numbers—it ingests granular clinical event logs directly from primary and secondary care Electronic Health Record (EHR) databases.

2. Ingested Data Layers: What Is Actually Being Pulled?

When your local NHS Trust connects its IT infrastructure to the regional Palantir FDP instance, automated Change-Data-Capture (CDC) listeners begin extracting data across four distinct layers of your medical history:

Data Layer Extracted Information Scope Primary NHS Source System Surveillance & Secondary Risk
01. Demographic & Identity NHS Number, Full Name, DOB, Postcode, Ethnicity, GP Practice Code Personal Demographics Service (PDS) Direct re-identification if cryptographic tokens are matched with external datasets.
02. Diagnostic & Clinical Notes SNOMED CT codes, consultation text, diagnostic codes, psychiatric flags EMIS Web / SystmOne / Epic Systems Unfiltered extraction of sensitive medical conditions without explicit patient consent.
03. Hospital Episode Statistics (HES) A&E attendance logs, admission/discharge timestamps, ward transfers Cerner Millennium / Epic EPR Continuous tracking of patient movements across NHS Trust boundaries.
04. Pathology & Prescriptions Full blood count results, histology reports, active medication lists Laboratory Information Systems (LIMS) Commercial health profiling and predictive risk modeling by third-party contractors.

While NHS England emphasizes that patient data is "pseudonymised" prior to processing, pseudonymisation is not anonymisation. Under UK GDPR Article 4(5), pseudonymised records remain personal data because the underlying cryptographic keys allow records to be re-identified when joined with administrative databases.

3. Decoding the Automated Extraction Pipeline

How does your clinical file travel from your local GP surgery or outpatient clinic into the central Palantir Foundry ontology?

The extraction process operates automatically in the background without requiring clinician intervention. When a doctor updates your file, database triggers copy the updated row into a local staging server. From there, encrypted pipeline connectors push the record into regional ICB data lakes powered by Palantir.

Governance Warning: Many regional NHS Trusts have deployed FDP data pipelines using generic gateway approvals, leaving local Caldicott Guardians with minimal visibility into which specific data tables are exported nightly to Palantir servers.

4. Action Guide: How to Force Your Local Trust to Disclose Extraction Logs

Under UK GDPR Article 15 and Data Protection Act 2018 Section 45, you possess an absolute statutory right to know whether your personal health data has been extracted, transformed, or ingested into the Palantir Federated Data Platform.

If you suspect your records have been exported to the FDP without explicit consent, copy the legal demand below and submit it directly to your local NHS Trust Data Protection Officer (DPO):

📜 FORMAL SUBJECT ACCESS REQUEST: PALANTIR FDP EXTRACTION AUDIT

Copy and paste this formal demand notice into an email to your local NHS Hospital Trust DPO and Caldicott Guardian:

To: Data Protection Officer & Caldicott Guardian [Insert Local NHS Trust Name] FORMAL SUBJECT ACCESS REQUEST — UK GDPR ARTICLE 15 RE: PALANTIR FEDERATED DATA PLATFORM (FDP) EXTRACTION & TELEMETRY AUDIT Patient Name: [Your Full Name] Date of Birth: [Your DOB] NHS Number: [Your 10-Digit NHS Number] Under UK GDPR Article 15 and DPA 2018 Section 45, I hereby exercise my legal right of access regarding all processing of my personal health data within the Palantir Federated Data Platform (FDP) network. Specifically, I demand full written confirmation and disclosure of: 1. Whether my clinical, demographic, or episode records have been exported, ingested, or transformed within any Palantir Foundry / FDP instance managed by this Trust or regional ICB. 2. The precise timestamped audit log detailing every automated extraction job that transferred my records from local EHR databases (e.g. Epic, Cerner, EMIS, SystmOne) into FDP staging pipeline tables. 3. Written evidence confirming whether my National Data Opt-out (Type 1 or National Opt-out) flag was applied at the ingestion boundary to filter my records prior to Palantir processing. 4. The exact third-party software vendor modules, algorithms, or sub-processors that have accessed my pseudonymised or unhashed data tokens within the FDP environment. Please supply this statutory information in a clear, human-readable electronic format within 30 calendar days as mandated by law. Signed, [Your Name] [Your Contact Address / Email]

💬 Formative Questions for Community Debate

Our public interest audit is driven by community oversight. Share your thoughts, experience, and local hospital responses in the comments below:

  1. Military Contractors in Health: Does using defense-grade analytics software developed for CIA/military targeting cross an ethical line when applied to civilian NHS medical notes?
  2. The Convenience vs. Surveillance Trade-off: Does the promise of shorter hospital waiting lists justify extracting millions of patient files into centralized corporate data lakes without explicit consent?
  3. Testing Local Transparency: If you submit a formal SAR asking your local hospital whether your records were exported to Palantir, do you expect them to provide clear access logs or claim "technical complexity"?