Patient privacy, not security, is what NHS bodies actually cite when they withhold information

2 September 2026

We've started pulling the full text of FOI responses themselves, not just titles and short excerpts — over 2,600 health & NHS documents now have real body text behind them, drawn from GOV.UK's own releases. Reading them in bulk turns up a pattern that's easy to miss one release at a time: health bodies protect a very specific kind of information, far more than any other part of this dataset does.

The personal-data gap

Section 40 — the exemption that protects identifiable personal data — is cited in 4.9% of health & NHS responses. That's nearly three times the rate in policing & justice responses (1.8%), despite policing generating enormous volumes of sensitive, identifiable data as a matter of routine. Health bodies invoke it more, not because they withhold more overall — their "does not hold" rate is actually slightly lower than policing's — but because when they do have a reason to say no, patient identity is disproportionately that reason.

Where that pattern comes from

One response in our sample makes the shape of the concern concrete rather than abstract. In 2017, the Office of the National Data Guardian released correspondence it had received about the Royal Free London NHS Foundation Trust's data-sharing arrangement with DeepMind, Google's AI research division — a case that became one of the more closely watched NHS data-governance disputes of the last decade. The response notes drily that the released letters were themselves "responses to letters released following a previous FOI also related to this work" — a data-sharing question that generated enough sustained public interest to produce a chain of separate requests over time, not just one.

That same underlying anxiety — who gets to see identifiable patient data, and on what terms — is visibly still live. Titles and descriptions in our current dataset show the NHS Federated Data Platform rollout as one of the most-mentioned live subjects in health FOI requests right now, years after the DeepMind case. It's the same question in new packaging: a national data-sharing infrastructure programme, attracting the same kind of scrutiny a single trust-level arrangement did in 2017.

What happens when nothing is withheld — and when it is

Most of what we can read in full is fairly mundane and fairly open: routine statistical releases, service reports, correspondence logs. But one response stands out for the opposite reason. In 2016, NHS Improvement commissioned Deloitte to review leadership at Princess Alexandra Hospital NHS Trust, and initially withheld the report. On internal review the following year, the decision to withhold was explicitly upheld, not reversed — a rarer outcome in our sample than a straightforward disclosure, and a genuine governance story rather than a procedural one.

That contrast is worth holding onto: health FOI responses read, on the whole, like a fairly open and procedurally light-touch system — see our piece on the MHRA's weekly disclosure rhythm for what "routine and high-volume" looks like at its most administrative. But where a request touches individually identifiable patient data, or an organisation's own leadership, that openness visibly tightens.

Reading this responsibly

This covers full response text from GOV.UK releases specifically — we haven't yet extended full-text reading to WhatDoTheyKnow's individual NHS trust requests, which sit behind stronger bot-protection than we've chosen to work around (see our about page for why, and our piece on why most trusts aren't in this dataset at all for the coverage gap that leaves). A document mentioning Section 40 isn't necessarily one where it was the operative reason for withholding — these are patterns in what responses talk about, not a case-by-case legal verdict.