All 2 Debates between Lord Tarassenko and Lord Russell of Liverpool

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Lord Tarassenko and Lord Russell of Liverpool
Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - -

My Lords, I shall speak in support of Amendment 83 in the name of the noble Baroness, Lady Kidron, to which I have added my name. In my speech, I will focus just on the aspects of the digital sovereign strategy that are relevant to the NHS. I speak as someone who held an honorary contract with the Oxford University Hospitals NHS Foundation Trust until November 2025, enabling me to be a co-investigator on research projects involving patient data.

Cyber attacks against NHS trusts and their supply chains occur with very high frequency, from regular automated phishing attempts, which are blocked daily, to major incidents causing significant clinical disruption. Health and social care consistently rank among the top sectors reported for cyber incidents and data breaches to the ICO. I am sure that we all remember the WannaCry cyber attack in May 2017, which affected 81 of our 236 NHS trusts at the time, causing nearly 20,000 appointments to be cancelled in a week.

Less than two years ago, in November 2024, there was a major cyber attack against the Wirral University Teaching Hospital NHS Foundation Trust, which compromised the trust’s electronic patient record. I know that EPR well as we have the same EPR in Oxford: Cerner Millennium. As a result of the cyber attack, staff in the Wirral hospitals lost all access to patient records, electronic prescribing tools and diagnostic results. All elective surgeries and outpatient appointments across the trust had to be cancelled, and members of the public were told not to use the emergency department at one of the hospitals in the trust. All clinical systems remained completely offline for nine days.

I mentioned the EPR Cerner Millennium. Cerner is now part of Oracle Health. Together, Oracle and Epic, both of which are US companies, account for about 40% of hospital EPR contracts in England and Wales. In primary care, EMIS software manages just under 60% of the patient records—the records of 35 to 40 million patients across England and Wales. EMIS was bought by Optum, part of the UnitedHealth Group, in 2023, but, in March this year, the UnitedHealth Group sold Optum to a US private equity firm, TPG, for just under £300 million. I will come back to that briefly later.

In 2023, NHS England and the Department of Health and Social Care launched a 2030 cyber security strategy. The noble Lord, Lord Markham, when he was a Health Minister, wrote the foreword—he will remember this, I am sure—to the strategy document. In it, he wrote—we all agree with him, I am sure—that

“the cyber security of our health and social care … underwrites patient safety”.

The group director for cyber security for the DHSC has recently written to all NHS trust boards informing them that, from this month, September 2026, new cyber policies will be included in the next data security and protection toolkit, covering issues such as multi-factor authentication, high-severity alerts and endpoint detection. There is nothing about AI, which is perhaps the subtitle of this Bill—something that will, I hope, have been removed by Report. Yet we know from Tuesday’s debate and last week’s open letter from 100 companies, including large tech firms, that AI-enabled cyber attacks are about to become more widespread and more sophisticated within months.

This prompts three questions. First, are officials from the Minister’s department, which has overall responsibility for cyber security, co-ordinating with the cyber security group in the DHSC—especially with respect to the latest threats from AI agents?

Secondly, have the recent reports from the AISI been communicated to the cyber security group in the DHSC, and have their implications for the NHS been discussed with them? I note here that the new Minister for Science and Innovation, Chris McDonald MP, is a Minister in both the DBIST and the DHSC, so I am hopeful that the answer to these two questions might be yes.

Thirdly, given the high prevalence of foreign ownership of companies, such as Epic and TPG, that are responsible for managing patient data within the NHS—notwithstanding the single-supplier agreement with Palantir, another US company, for the Federated Data Platform—has the Minister’s department assessed the risk to relevant network and information systems as a result of our technological dependence on these companies?

What I have described for the NHS also applies to other sovereign data assets such as those held by the BBC or the Met Office. If the full value to the UK of these sovereign data assets is to be realised as part of the Government’s growth strategy, we need to be optimally protected against cyber attacks, including AI-enabled attacks. For that to happen, we need a coherent digital sovereign strategy across government departments, led by the Minister’s department.

Lord Russell of Liverpool Portrait Lord Russell of Liverpool (CB)
- Hansard - - - Excerpts

My Lords, I echo the words of the noble Baroness, Lady Kidron: in the previous group, we probably would not have had anything like that debate if a clear strategy were indeed in place.

I will speak very briefly and in the context of other countries’ views of the safety and security of doing business with the UK and UK entities. Part of the backdrop is an attempt by His Majesty’s Government to try to do a reset with the EU, not least because of the problems we are having with our erstwhile colonial possessions across the Atlantic. We need to be viewed as a safe haven for the security of our business and data. If we look at what the EU, for all its bureaucratic idiosyncrasies, has been doing with NIS2, in many instances that is an extremely good model for us when looking comprehensively at the different sectors that need to be involved. NIS2 covers energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ISP services, public administration, space, postal services, waste management, chemicals, food, manufacturing, research and other critical parts of the economy. The EU is ahead of us and has done a great deal of groundwork; if we were to talk to the EU, we could benefit hugely without reinventing the wheel.

It is imperative not only that we give noble Lords and parliamentarians a feeling that we know what we are doing and where we are going but that other countries currently doing, or thinking of doing, business or more business with us have faith in the security of our data and cyber security infrastructure. If I were looking to invest in a company, that is an area I would look at very carefully—but, frankly, at the moment, I would not feel very confident.

Data (Use and Access) Bill [HL]

Debate between Lord Tarassenko and Lord Russell of Liverpool
Lord Russell of Liverpool Portrait The Deputy Chairman of Committees (Lord Russell of Liverpool) (CB)
- Hansard - - - Excerpts

My Lords, before we proceed, I draw to the attention of the Committee that we have a hard stop at 8.45 pm and we have committed to try to finish the Bill this evening. Could noble Lords please speak quickly and, if possible, concisely?

Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - -

My Lords, I support my noble friend Lady Kidron’s Amendment 211, to which I have put my name. I speak not as a technophobe but as a card-carrying technophile. I declare an interest as, for the past 15 years, I have been involved in the development of algorithms to analyse NHS data, mostly from acute NHS trusts. This is possible under current regulations, because all the research projects have received medical research ethics approval, and I hold an honorary contract with the local NHS trust.

This amendment is, in effect, designed to scale up existing provisions and make sure that they are applied to public sector data sources such as NHS data. By classifying such data as sovereign data assets, it would be possible to make it available not only to individual researchers but to industry—UK-based SMEs and pharmaceutical and big tech companies—under controlled conditions. One of these conditions, as indicated by proposed new subsection (6), is to require a business model where income is generated for the relevant UK government department from access fees paid by authorised licence holders. Each government department should ensure that the public sector data it transfers to the national data library is classified as a sovereign data asset, which can then be accessed securely through APIs acting

“as bridges between each sovereign data asset and the client software of the authorized licence holders”.

In the time available, I will consider the Department of Health and Social Care. The report of the Sudlow review, Uniting the UK’s Health Data: A Huge Opportunity for Society, published last month, sets out what could be achieved though linking multiple NHS data sources. The Academy of Medical Sciences has fully endorsed the report:

“The Sudlow recommendations can make the UK’s health data a truly national asset, improving both patient care and driving economic development”.


There is little difference, if any, between health data being “a truly national asset” and “a sovereign asset”.

Generative AI has the potential to extract clinical value from linked datasets in the various secure data environments within the NHS and to deliver a step change in patient care. It also has the potential to deliver economic value, as the application of AI models to these rich, multimodal datasets will lead to innovative software products being developed for early diagnosis and personalised treatment.

However, it seems that the rush to generate economic value is preceding the establishment of a transparent licensing system, as in proposed new subsection (3), and the setting up of a coherent business model, as in proposed new subsection (6). As my noble friend Lady Kidron pointed out, the provisions in this amendment are urgently needed, especially as the chief data and analytics officer at NHS England is reported as having said, at a recent event organised by the Health Service Journal and IBM, that the national federated data platform will soon be used to train different types of AI model. The two models mentioned in the speech were OpenAI’s proprietary ChatGPT model and Google’s medical AI, which is based on its proprietary large language model, Gemini. So, the patient data in the national federated data platform being built by Palantir, which is a US company, is, in effect, being made available to fine-tune large language models pretrained by OpenAI and Google—two big US tech companies.

As a recent editorial in the British Medical Journal argued:

“This risks leaving the NHS vulnerable to exploitation by private technology companies whose offers to ‘assist’ with infrastructure development could result in loss of control over valuable public assets”.


It is vital for the health of the UK public sector that there is no loss of control resulting from premature agreements with big tech companies. These US companies seek privileged access to highly valuable assets which consist of personal data collected from UK citizens. The Government must, as a high priority, determine the rules for access to these sovereign data assets along the lines outlined in this amendment. I urge the Minister to take on board both the aims and the practicalities of this amendment before any damaging loss of control.