Doctors, MPs and campaigners are demanding greater scrutiny after a US private equity firm acquired the company behind the electronic patient record system used by most GP practices in England.
TPG has bought Optum UK from the American healthcare corporation UnitedHealth Group in a deal reported to be worth around $400 million, equivalent to approximately £300 million.
Optum UK includes EMIS, one of the NHS’s most important technology suppliers. Its software allows GPs to create and manage electronic medical records, prescribe medicines and share information needed to provide care. The scale of EMIS’s role means the company’s systems contain records relating to millions of patients. Critics are concerned that ownership of such a significant part of NHS infrastructure has changed hands without sufficient public debate.
However, the takeover does not give TPG an unrestricted legal right to read or use individual medical records. GP practices remain the data controllers responsible for their patients’ information, while EMIS generally operates as a data processor under NHS contracts and UK data-protection law. The concern is therefore less that TPG executives can suddenly open individual medical files and more that a private equity company now owns technology on which much of English general practice depends.
Not the first NHS data row this year
This is far from an isolated controversy. The NHS’s own Federated Data Platform, run by Palantir, was previously found to have granted contractors “unlimited access” to patient data, with the NHS’s own officials warning internally that it risked a “loss of public confidence.” An investigation subsequently found Palantir had hired 32 senior UK government officials, including former NHS and MoD AI chiefs, raising separate questions about the closeness between the company and the officials who’d overseen its contracts.
That pressure eventually told: Andy Burnham moved to scrap Palantir from the NHS data deal in one of the earliest tests of his premiership, and ministers had already begun exploring breaking the £330m Palantir NHS contract amid growing political pressure. Separately, Palantir accused Sadiq Khan of “putting politics above public safety” after he blocked a Met Police contract, a row that also exposed a genuine split within Labour over how comfortable the party actually is with US tech firms holding this much NHS and policing data.
The EMIS acquisition lands squarely in that same pattern: sensitive NHS infrastructure changing hands, or facing fresh scrutiny, with limited public involvement in the decision either way.
‘Private equity now owns the plumbing’
The Doctors’ Association UK said the acquisition should concern anybody who cares about the future control and security of NHS infrastructure. “Private equity now owns the plumbing of English general practice,” a spokesperson said. “The GP records of more than half the country sit on a system controlled by a firm whose business model is returns for investors, not care for patients, and the public found out after the fact.”
The organisation called on the government to explain what safeguards would apply if TPG eventually sold the business to another investor, and questioned why an acquisition involving such an important NHS supplier was not subjected to parliamentary scrutiny.
EMIS has been part of the technology supporting British general practice for nearly three decades. That longevity means changing its ownership is not comparable to the sale of an ordinary software business. GP surgeries rely on its systems to access medical histories, review test results and prescribe treatments. Any disruption, change in commercial strategy or deterioration in the service could have consequences across primary care.
What ownership does and does not mean
The suggestion that NHS records have simply been handed over to an American investment company requires some qualification.
Under data-protection rules, individual GP practices remain responsible for the patient information they hold. They determine why and how it is processed and must ensure access is limited to people with a legitimate reason to use it. EMIS provides and hosts the software through which many of those records are managed. In that capacity, it acts as a data processor and must follow the written instructions of the relevant NHS organisation or GP practice.
TPG says its acquisition of the company does not allow it to access, maintain, control or exploit NHS patient records. “A change in ownership of the company has in no way changed how patient data is stored, protected or governed, nor has it altered the legal, regulatory, contractual and operational safeguards that apply,” a spokesperson said. The firm added that it would support EMIS’s existing standards for patient privacy and data protection.
The distinction matters, but it does not make questions about ownership irrelevant. A private equity owner can influence investment, staffing, product development, pricing and the future sale of the business, even where it cannot lawfully use the underlying patient information for its own purposes.
Liberal Democrats demand greater scrutiny
Liberal Democrat health spokesperson Helen Morgan accused the government of allowing strategically important deals to proceed without sufficient protection for patients. “Time and time again, patients are seeing the government hand over sensitive NHS data to US tech firms, leaving our public services dangerously exposed,” she said.
Morgan called on ministers to provide greater support for British healthcare technology companies rather than allowing critical NHS infrastructure to become increasingly dependent on overseas businesses.
The acquisition was examined by the government under the National Security and Investment Act 2021 and approved through the applicable process. That review considers whether a takeover presents a risk to national security. It is not the same as a parliamentary inquiry into the broader consequences of private equity ownership, including future investment decisions, commercial pressures and the long-term resilience of NHS technology.
Concerns about TPG’s healthcare record
Campaigners have also raised questions about TPG’s wider healthcare investments. An investigation by the International Consortium of Investigative Journalists examined hospitals in Kenya belonging to Evercare, a healthcare group backed by TPG’s Rise Fund. The investigation reported allegations that some patients accumulated severe debts and, in certain cases, were asked to provide land deeds as security for unpaid bills.
TPG strongly disputed the reporting and rejected any suggestion that it or Evercare put profit before patients. The company said it had invested more than $100 million in Evercare over six years, improving the quality and accessibility of treatment as well as strengthening clinical standards and patient protections.
Anna Marriott, formerly Oxfam’s health policy lead, said the NHS deal should still “ring major alarm bells.” “It is deeply concerning that a private equity firm with a highly controversial track record in healthcare internationally can take control of sensitive NHS patient data with so little public scrutiny,” she said. Marriott argued that patients cannot choose which company supplies the software used by their GP, placing a greater responsibility on the government to ensure that their information and the infrastructure surrounding it remain secure.
EMIS says protections remain unchanged
EMIS said patient privacy and data security would continue to sit at the centre of its operations. A spokesperson said the company was subject to rigorous controls, strict access requirements and contractual and regulatory obligations that would not change following the takeover. “Any suggestion that this acquisition changes patient data protections disregards nearly three decades of upholding only the strictest compliance standards,” the company said.
TPG offered an even more direct denial of suggestions that it had gained control over the records themselves. “Assertions that TPG could in any way access, control, maintain or utilise NHS patient records are entirely false,” its spokesperson said.
These assurances address the immediate fear that ownership automatically provides access to identifiable medical information. They do not settle the broader argument about whether companies providing critical NHS systems should be bought and sold with limited public involvement.
Why campaigners remain concerned
Electronic GP records contain some of the most sensitive information held about any individual, including diagnoses, prescriptions, test results and details disclosed in confidence to healthcare professionals. Even when access is tightly controlled, the software hosting and managing that information forms part of Britain’s critical national infrastructure.
Private equity firms usually acquire businesses with the intention of improving their value before eventually selling them or extracting returns for investors. Critics worry that this model can encourage cost-cutting, additional borrowing or changes in commercial strategy that may not align with the long-term needs of the NHS. There is no evidence that TPG intends to weaken security or misuse patient information, and doing so would breach data-protection law and its contractual obligations.
The more substantial question, and the same one that dogged the Palantir contract before it, is whether existing rules are strong enough to protect the NHS from decisions that could affect service quality, costs and technological dependence without involving any direct misuse of data.
The government approved the transaction under existing legislation, while EMIS and TPG insist nothing has changed for patients. For doctors and campaigners, that is not quite the same as demonstrating that nothing ever could.
One response to “Alarm as US private equity firm takes ownership of company handling millions of NHS GP records”
-
I do not want a tech firm from an increasingly unfriendly and unstable country, especially one with a law that allows their govt to demand access to data that the firm may hold overseas. I do not want my data, especially data about my ill health, used by a private equity firm for the purposes of making them and their investors rich. In short, these firms are misery pimps, selling my pain for their gain. “There is no evidence that TPG intends to weaken security or misuse patient data… doing so would breach data protection laws and its contractual obligations,” just like the private water companies wouldn’t dump sewerage, as its against our laws and their contractual obligations, but they’re not only doing it, and have been since privatisation, they’re demanding a slackening of said law! So they will simply act in the best interests of their investors, not us patients.












Leave a Reply