NHS: In-house Software Capabilities Debate

Full Debate: Read Full Debate
Department: Department of Health and Social Care

NHS: In-house Software Capabilities

Lord Kamall Excerpts
Monday 16th March 2026

(1 day, 10 hours ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Merron Portrait Baroness Merron (Lab)
- View Speech - Hansard - - - Excerpts

Cyber attacks across our whole government are extremely concerning, and that is why we have built resilience. On health and social care specifically, I can assure the noble Lord that, in 2025-26, we invested £75 million across health and social care; that built on the £375 million invested since 2017. When I had responsibility for the blood transfusion service, my own experience was that, where there was a cyber attack, we had the systems in place.

Lord Kamall Portrait Lord Kamall (Con)
- View Speech - Hansard - -

My Lords, there is always a very difficult balance between keeping something in-house or outsourcing it, and we should not forget the national programme for IT in the NHS in the early 2000s, which ended up costing between £10 billion and £20 billion. My question is on the company Palantir. The Minister will be aware that there are a range of views on Palantir. Some say that it is the best software available and that no one can match it; others say that they are worried that it will lock the NHS in long-term and scrape data for other uses. What specific measures have NHS England and the department put in place so that, in the event that the Palantir contract is not renewed, the healthcare system will be able to move seamlessly to another supplier?

Baroness Merron Portrait Baroness Merron (Lab)
- View Speech - Hansard - - - Excerpts

That seamless movement is an important point generally, but the federated data platform does not centralise or sell patient data. Data remains firmly under NHS control, and access is strictly governed. It is fully auditable and used only for approved patient benefit and NHS benefit. Palantir operates strictly under the instruction of NHS England and it does not, as I said, own or control NHS data. That access is tightly governed. In response to the earlier question, I note that the federated data platform to which the noble Lord refers is cyber resilient and subject to rigorous contractual, legal and information governance controls.