-
Healthcare
-

The FTC Is Looking At Epic. The NHS Should Be Asking Who Really Controls Its Data

By
Distilled Post Editorial Team

There has been no finding of any wrongdoing, and Epic disputes allegations of anticompetitive behaviour. For the NHS, however, the significance is much bigger than one company or one investigation. It raises a more uncomfortable question: when a health service becomes deeply dependent on a technology platform, who really controls the data?

The NHS is rapidly becoming a data dependent organisation. Electronic patient records, the Single Patient Record, the Federated Data Platform, artificial intelligence, predictive analytics, population health and increasingly automated clinical pathways all depend on information moving safely and reliably between systems. That makes interoperability much more than an IT specification. It is becoming critical infrastructure. The question is no longer simply who legally controls a patient record. The real question is who controls whether that record can move, be connected, be reused and be transferred to another platform. A trust may remain the legal data controller while becoming operationally dependent on a supplier to extract, migrate or integrate its own information. Those are not the same thing. Owning data on paper is not enough if leaving the system becomes prohibitively expensive, technically difficult or operationally unsafe.

This is where the NHS should pay close attention. Healthcare technology naturally rewards scale. The more hospitals that use a platform, the more integrations it supports. The more information flowing through it, the more valuable the ecosystem becomes. The more deeply it becomes embedded in clinical workflows, the harder it becomes to replace. None of that is inherently a problem. The problem begins when integration becomes dependency. An NHS organisation should be able to introduce another authorised system without unnecessary barriers, extract information in a usable format, allow patients to move between providers without losing continuity, and enable legitimate research and innovation under appropriate governance. Most importantly, it should know that it can change supplier. If moving away from a platform becomes so expensive, disruptive or technically complex that no realistic alternative exists, then competition becomes theoretical. The NHS may technically own its information while the practical power sits elsewhere. That is not meaningful data sovereignty. It is dependency with ownership paperwork attached.

The consequences go beyond procurement. Public confidence in NHS data has traditionally centred on privacy, cyber security and whether information is being used appropriately. That definition is now too narrow. Patients need confidence that their information will be available wherever they receive care. Clinicians need confidence that records are complete. NHS boards need confidence that hospitals can continue operating safely if a supplier relationship changes. Government needs confidence that billions invested in digital transformation are building NHS capability rather than creating permanent technological dependencies. The technology market also needs confidence that new companies can compete on quality and innovation rather than being excluded because existing platforms are too difficult to connect with. Without that confidence, interoperability risks becoming something the NHS talks about rather than something it actually possesses.

Artificial intelligence makes the issue more urgent. AI systems depend on access to clean, timely and connected information. Predictive models, clinical decision support, automated pathways and population health tools become significantly less useful when the underlying data is fragmented or difficult to access. The NHS could therefore spend heavily on AI while discovering that its ability to deploy new technology is constrained by the architecture underneath it. A data access problem quickly becomes an innovation problem, then a productivity problem, and eventually a patient care problem.

The answer is not to reject Epic or any other major technology supplier. Large EPR platforms have transformed clinical workflows and created capabilities that many hospitals could never build independently. The answer is stronger governance. Five straightforward questions should be covered by every significant NHS technology contract: Is it possible for us to fully and usably extract our data? Can another authorised system connect to it? Can another supplier realistically compete? Do we understand the full cost and complexity of leaving? Could we continue operating safely if the supplier relationship ended? These questions should sit alongside cyber security, clinical safety and financial value at NHS board level because vendor dependency is increasingly a strategic and clinical risk.

The lesson from the scrutiny in America is therefore not about one company. It is about the architecture of modern healthcare. The NHS is moving towards a future in which hospitals, clinicians, researchers and AI systems depend on a continuous flow of patient information. That makes control of data movement almost as important as ownership of the data itself. The principle should be simple: NHS data must never become easier to put into a system than to get out of it. Because the real test of data sovereignty is not who owns the record. It is who has the power to move it.