惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
Security Archives - TechRepublic
Security Archives - TechRepublic
V
Vulnerabilities – Threatpost
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Proofpoint News Feed
G
GRAHAM CLULEY
P
Privacy International News Feed
The Hacker News
The Hacker News
Forbes - Security
Forbes - Security
U
Unit 42
N
News and Events Feed by Topic
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cyber Attacks, Cyber Crime and Cyber Security
C
Cisco Blogs
A
About on SuperTechFans
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
D
Docker
I
Intezer
Spread Privacy
Spread Privacy
The Last Watchdog
The Last Watchdog
V2EX - 技术
V2EX - 技术
S
Security @ Cisco Blogs
F
Full Disclosure
S
Secure Thoughts
M
MIT News - Artificial intelligence
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
W
WeLiveSecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Project Zero
Project Zero
Recorded Future
Recorded Future
Cyberwarzone
Cyberwarzone
S
Security Affairs
AWS News Blog
AWS News Blog
H
Help Net Security
The GitHub Blog
The GitHub Blog
Hacker News: Ask HN
Hacker News: Ask HN
Vercel News
Vercel News
P
Proofpoint News Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The Register - Security
The Register - Security
S
Schneier on Security
F
Fortinet All Blogs
C
CERT Recently Published Vulnerability Notes
L
LINUX DO - 最新话题
T
Tor Project blog
T
The Exploit Database - CXSecurity.com
MongoDB | Blog
MongoDB | Blog
Webroot Blog
Webroot Blog

medConfidential

Ministers promised you’d control your data. The Health Bill and NHS England say otherwise The Coming NHS They Didn’t Campaign On A Plan for The Medium Goodbye to Palantir Biobank’s assurances get broken yet again Biobank’s assurances get broken yet again Ministers choose silence on coverups and data abuses by Ghouls and Creeps Second Reading of the Health Bill – enabling and empowering Ghouls and Creeps A quick look at the proposed English NHS Online Hospital medConfidential Bulletin, 22nd May 2026 Wes Streeting’s final Bill | medConfidential Streeting resigns | medConfidential King’s Speech | medConfidential Biobank’s (April) Breach in Context The latest Biobank Screwup (April 2026) Why the Biobank breaches matter to you Mr Streeting is breaking promises, you still have choices Dog Cancer – is cancer treatment for your dog becoming better than treatment for your grandma, or your kids? The latest (March 2026) Biobank mess (and consequences for everyone else) The Covid Inquiry Module Reports Government tells NHS that GPs should misinform to patients Moving Parts: Current and Imminent Government plans for your medical records 10 Feb re-announcement of Biobank and others getting data in ways the public were told wouldn’t happen MedConfidential Bulletin – 19 December 2025 “Making [Palantir] irreplaceable” to the NHS in England (and beyond) – (Part II)
Critical Intellectual Property of the NHS Canonical Data Model is controlled by Palantir
by medcon · 2026-06-12 · via medConfidential

NHS employers may own the work NHS staff did within the Federated Data Platform, and they do, but when one former former NHS staffer writes “The Canonical Data Model belongs to the NHS, is licensed via the Open Government Licence, and is available to all on GitHub”, but omits to give the link which shows:

  • when you read the PDF, the word “palantir” is nowhere to be found – yet in the Model description itself palantir are everywhere, from:
    • “servers: – url: https://ptukhealth.palantirfoundry.co.uk” (it’s especially notable that this isn’t an nhs.uk address and doesn’t even reference the NHS – this is not NHS owned);
    • “paths: /api/v2/ontologies/palantirukhealth-ontology/objects/Admission”;
    • with over 1000 mentions of Foundry and over 1000 of Palantir, including:
      • “title: Palantir OpenAPI”;
      • “description: The Palantir REST API. Please see https://www.palantir.com/docs for more details.” 

That repository does not say how the PDF is built from the model, so it is impossible to tell (from outside the Palantir office) whether the difference between the PDF and spec is deliberate, an it is why open source matters in standards and specifications.

Some FDP advocates may claim that the ontology is owned by the NHS, but Palantir clearly has scope to disagree – and when it matters, the repeatedly litigious Palantir can and likely will deploy their lawyers to block use elsewhere with which they disagree. 

What to do about it

The NHS could deploy Claude to regenerate the ontology from NHS data, and update all the code, but that’s going around Palantir’s ownership of something the NHS doesn’t own or control – as to quote an FDP advocate: “The CDM would need to be reimplemented”, because the NHS doesn’t own or control it.

The CDM must be reimplemented by the NHS without touching any Palantir IP, and Palantir must certify that there are no Palantir rights engaged, before any NHS body signs any future contract with Palantir. If Palantir wishes to hold patients hostage the way FDP advocates suggest Palantir would hold cancer patients hostage, then that should encourage migration sooner rather than later.

Which is the core practical point of the criticism of Palantir and the current v1 FDP – Palantir can block patient benefits and limit NHS choices if it chose to. There are a few key chokepoints, and they must all be resolved (Cancer360 is the main patient facing one we cover elsewhere.)

===

Find out what happens next: Sign up for our newsletter (we don’t email often) or get small frequent updates via our free Substack – updates are free to read; we’re very grateful to all who can support our work with a Monthly or Annual subscription, or make a regular or one-off donation.