Britain gave Palantir access to sensitive COVID-19 patient records in £1 deal
cnbc.com
cnbc.com
"The contract, known as a data-sharing agreement, was published Friday by politics website OpenDemocracy and law firm Foxglove alongside similar contracts with Google, Microsoft, and U.K. AI start-up Faculty."
"The contracts show Palantir charged only £1 ($1.27) for use of its Foundry data management software while Google offered “technical, advisory and other support” for free."
This is about a lot more than just Palantir. And the NHS has been in hot water for handing out sensitive patient data to tech firms before. :/
Without the perspective of someone who works in the NHS with Palantir's software, it's impossible to say if the NHS and the public got a good deal.
Who can promise that there are no side channels to the USA or no covert exfiltration using "backups" or "integration systems"?
In other cases, data has been outright sold: https://www.theguardian.com/politics/2019/dec/07/nhs-medical...
And what do you think why Palantir and the other offer their services for one pound?! It's all about that data. https://www.wired.co.uk/article/google-apple-amazon-nhs-heal...
They already have that. Read the Lansley reforms. They mostly don't take it up because they can't afford to run healthcare for the pittance paid by UK government, but there are large bits of the NHS run by non-NHS providers. See for example Priory Group or Cygnet Health Care.
They specifically do not. You consuming twitter bubble fake news doesn't make something true
And, actually tracing back how a machine learning algorithm might have gobbled up this data, to be used in 5 years in a way that no one can predict, is not easy either.
When it comes to how to solve this I really think we need to fundamentally rethink data ownership both on a legal as well at a technical level. I was recently reading up on Tim Berners-Lee's SOLID and I think something like that should be the default for all our data. We store our own healthcare data in something akin to a pod, when the NHS uses that data they get access to it granted by the patient in a way that puts formal limits on what they can do with it and how long they have access to it, and I as the patient have both the right and technical ability to revoke that access. We really need to push for data ownership and strong guarantees for data rather than this through the backdoor process of shoving private health data to unaccountable firms.
Maybe this is something where all these smart contract and decentralisation technologies can play a meaningful role rather than being primarily used for speculative currencies.
If that's what SOLID is, its a scam and more of his DRM promotion. There is no technical way to "revoke my access." Unless you have a memory erasing implant in my brain, if the data gets onto my screen, I can copy it and access it forever. Period. Fuck Tim Berners-Lee.
Imagine for example, if the US or UK governments took corporate misuse of personal health data (https://www.theverge.com/2019/6/27/18760935/google-medical-d...) as seriously as they currently takes video copyright violations by individuals....
The citizens would still have to agree to allowing their personal data to be processed by third-parties and consent for their data to be processed outside the EU.
Is there any evidence that this consent was given?
This title really seems like click-bait.
Palantir received one pound; the government paid Palantir for software. The title implies that the government was selling the data, but they were actually getting SaaS for a pittance.
No ambiguity there, although it doesn't adequately explain how that came about, but that's why there's an article.
Is the argument against this that the NHS not be allowed to use any cloud infrastructure, and that everything ought to be on-premise?
Why would any government consent to working with Palantir if they had any suspicion that their data might be used by US government clandestine agencies?
As far as I'm aware, Palantir doesn't claim to share data between its customers. It works with governments all over the world — ostensibly this means that either Palantir agrees to not share its customers data with other customers, or every government is implicitly consenting to their citizens' data being accessed by every other government.
Of all the competent devs / data analyst in the UK, how many do you think actually want to work at the NHS?
So lots of demand / need (healthcare is a mess in part because of data management via paper) and no supply / interest of talent.
https://i.imgur.com/iab51Zq.png
From OECD https://data.oecd.org/healthres/health-spending.htm
https://www.ifs.org.uk/uploads/images/election2017_images/bn...
https://www.ifs.org.uk/publications/9186
Perhaps a more fair statement to make would be that demand for NHS services has seen a dramatic increase since 1997 and as a consequence it's budget has seen dramatic adjustments.
Total health spending in England was around £129 billion in 2018/19 and is expected to rise to nearly £134 billion by 2019/20, taking inflation into account.
The salaries aren't definitely not great compared with London...but they aren't terrible outside. I think the issue is that being a "dev" in the NHS is nothing like being an actual dev anywhere else. It is mostly about learning proprietary software, not development. So there are no real transferable skills (and ofc, NHS Trusts is always do "internal hires").
I have seen this in other businesses. They have huge IT departments but it is mostly about maintaining proprietary software (like SharePoint or whatever). The business then changed to a tech business and they have hundreds of IT people who have no useful skills (and the issue is management, in the NHS you have managers who are from the last century...no wonder Palantir rolled them).
(Somewhat ironically, one of these businesses actually employs a few top CS grads but they all work in the non-IT side of business...the issue is management in the UK not understanding what IT is for at a fundamental level).
[0] https://ec.europa.eu/info/about-european-commission/what-eur...
http://www.legislation.gov.uk/ukpga/2018/16/crossheading/ret...