top of page

The Health Bill Reaches Report Stage — But Nobody Has Answered Who Actually Holds the Nation's Data (CivicTwin)

Sep 2
5 min read

by The Rev Rabbi Eliyahu Leib Goldsobel Esq.

(Assistive technology was used as per the Equality Act 2010 s 20)

the image was created by a generative AI tool
the image was created by a generative AI tool

On 7 September, the Health Bill 2026–27 returns to the House of Commons for report stage, the last chance for MPs to amend it before it moves toward Royal Assent. Introduced in May and sponsored by Health Secretary Wes Streeting's successor at the despatch box, James Murray, the bill's headline act is the abolition of NHS England — "the world's largest quango," in the government's own words — with its functions redistributed between Integrated Care Boards and the Department of Health and Social Care. That alone would be the biggest structural change to NHS governance in a generation. But buried inside the same bill is a second, quieter ambition that deserves at least as much scrutiny: a legal footing for the Single Patient Record, and with it, an unresolved question about who actually controls the country's most sensitive dataset.


A bill that centralises power in two directions at once 


The Health Bill does two things simultaneously, and they pull in opposite directions on the question of trust. On one hand, it hands the Secretary of State sweeping new powers: to direct Integrated Care Boards, to appoint and de-authorise foundation trust chairs, and to become, in effect, data controller for a patient record system meant to span every GP surgery, hospital, ambulance service and community pharmacy in England. On the other hand, it strips out two of the independent bodies that currently exist to check that power: Healthwatch England, the statutory patient voice, and the Health Services Safety Investigations Body, the "safe space" investigator modelled on air-accident inquiries and built explicitly to operate without blame or liability so it can find the truth. Both are being folded into a new patient experience directorate sitting inside the same department the bill is busy empowering. 


Put simply: the bill centralises data and decision making in the Secretary of State's office, while removing two of the independent mechanisms that would otherwise hold that office accountable for how it uses either.


The Palantir problem the bill doesn't mention 


Nowhere in the bill's text does the word "Palantir" appear. But nobody following NHS data policy believes the Single Patient Record can be discussed without it. The Federated Data Platform — the £330 million infrastructure project that underpins much of the interoperability the SPR depends on — has been run by Palantir since 2023, and NHS England has already confirmed that Palantir staff can hold an "admin" role granting access to identifiable patient data before it is pseudonymised. An internal briefing note seen by the Financial Times warned this risked a "loss of public confidence" in NHS England's own assurances. Patients cannot opt out of the platform, even if their own hospital trust can. And in a recent interview, Mr Murray himself confirmed that the Palantir contract "is being reviewed at the moment ahead of its breakpoint next year" — an admission that the government itself is not settled on the current arrangement, even as it legislates the record-keeping architecture that arrangement will underpin. 


This is not a fringe objection. It is the government's own health secretary flagging uncertainty about the single vendor his department is legislating around. Vendor lock-in of this kind is a well-understood risk in public procurement — you hand over not just money but the benefit of learning from the data itself, to a company chaired by someone who has publicly called for the NHS to be privatised. Locking a single contractor into the substrate of the nation's health data, at the same moment the independent bodies designed to scrutinise that substrate are abolished, is not a coincidence worth ignoring. It is a design choice, and report stage is the only remaining opportunity to amend it. 


A wider pattern of accountability moving the wrong way 


There is a useful comparison sitting in a different bill entirely. The Immigration and Asylum Bill, introduced the same summer, reforms section 54 of the Modern Slavery Act — moving supply-chain transparency from a voluntary "comply or explain" exercise toward mandatory, prescriptive reporting with financial penalties, because the old regime was, in the government's own assessment, a "toothless tiger." Parliament has accepted, in that context, that voluntary transparency does not produce accountability — that enforceable structure is required before trust can be justified. 


The Health Bill asks the public to extend precisely the trust that section 54 reform concludes should no longer be assumed on trust alone — and does so for something more intimate than a supply chain: a person's complete medical history, shared with a private contractor, without opt-out, while the independent bodies built to investigate failures of that trust are dissolved into the same department holding the keys. 


Why this is a design problem, not just a procurement problem 


The instinct to build a Single Patient Record is right. Fragmented records genuinely harm patients — delayed diagnoses, repeated tests, discharge delays, maternity and frailty care that falls through the cracks between services. The government's own aim, that patients should see their own record securely on the NHS App, is the correct aim. The failure is not in the ambition; it is in treating vendor concentration and centralised ministerial control as the only route to interoperability, when it is simply the path of least resistance. 


An alternative exists in principle, and it is the one I have been building through my own research into agency, presence, and institution design: a person centred architecture where the patient — not the contractor, not even the department — is the actual point of control. This is the premise behind CivicTwin, a research tool developed alongside doctoral work on institutional omission and the corrosion of agency in public-sector decision-making. Rather than a single admin-level access point sitting with an external vendor, a CivicTwin-style model treats the patient's own record as the sovereign unit: auditable by the patient, portable across providers, and structurally incapable of the kind of "unlimited access" arrangement now under scrutiny at NHS England. It does not require abandoning federation or interoperability — it requires building those things around the person whose data it is, rather than around the convenience of the department or the contractor managing it on the department's behalf. 


What report stage should actually do 


MPs returning to this bill on 7 September have a narrow but real opportunity: to attach patient opt-out rights to any Palantir-linked infrastructure underpinning the Single Patient Record; to preserve an independent investigatory function equivalent to HSSIB rather than folding safety investigation into the same department that will hold the data; and to require that any future single-vendor data contract be reviewed against the same standard of enforceable accountability that Parliament is, in a different bill this same session, imposing on ordinary supply chains. A health data system built without those safeguards will not fail because the ambition was wrong. It will fail the way institutional trust always fails — quietly, procedurally, and only becoming visible once the person it was meant to serve has already been let down by it.

Please reach out for more details regarding CivicTwin

 
 
 

Comments


smeclimatehub-dark.webp

Subscribe to Our Newsletter

Thanks for submitting!

  • Blogger
  • Pinterest
  • Flickr
  • Instagram
  • Twitter
  • YouTube
  • RSS
dc_badge2.png

☎️+44 (0) 203 093 1860

  © 2021-2026

  The Westminster Gazette Limited 

              All rights reserved        

 7 Bell Yard, London, England, WC2A 2JR

bottom of page