Back to Blog

Private Equity Now Owns the Software Running Your Patients' GP Records

Sep 02, 2026
Private Equity Now Owns the Software Running Your Patients' GP Records

The NHS Support Federation published a report on September 1, 2026 documenting something that had been creeping up quietly for years: private equity firms now own the companies behind the major IT systems used in most GP practices across England. EMIS, SystmOne, Vision. The infrastructure that holds NHS patient records, referral histories, medication lists. Owned, or significantly backed, by funds whose primary obligation is to their investors.

That's an NHS story, you might think. Your clinic runs its own systems.

But here's where it gets relevant to you. Your patients are also registered at GP practices. Their records flow between your clinic and those practices, or they should. And if your patients (or your staff, or your accountant) ever assumed that "NHS data" and "private clinic data" exist in cleanly separate silos, the Federation's report is worth sitting with for a while.

What the report actually says

The NHS Support Federation's concern is concentrated on conflicts of interest and data governance: who owns these systems, what rights they hold over the data processed through them, and whether NHS commissioners have adequate oversight. Their worry is less about active malfeasance and more about structural opacity. When a fund buys a GP IT supplier, the contractual arrangements around patient data don't automatically become public. The NHS doesn't always renegotiate terms. And the incentives of a private equity-backed company are not identical to the incentives of a company whose sole customer is the public sector.

For private clinics, the direct exposure is indirect but real. When a patient brings a referral letter from their GP, that letter was generated by one of these systems. When you send a discharge summary or a letter back to the GP, it lands in one. The data about your patient's contact with your service sits in that ecosystem, even if your own records are entirely separate.

Why this matters more if you share data with GPs

Not every private clinic has close GP relationships. A standalone aesthetics clinic doing skin treatments may have almost no data flowing to or from GP practices. But if you run a private GP service, a mental health clinic, a physiotherapy practice, a diagnostics service, or anything that sits closer to the NHS referral pathway, the boundary between "their systems" and "yours" is thinner than you might assume.

The GDPR question is straightforward in theory: who is the data controller, who is the processor, and what does the processing agreement say? In practice, many private clinics have never mapped exactly where patient data goes after it leaves their own records system. A referral letter goes out. Does it get scanned and stored by the receiving GP system? Almost certainly. Does your clinic have a record of that? Probably not. Does your privacy notice mention it? I'd be surprised if it did, for most clinics.

This isn't a new problem. The Federation's report just makes it harder to ignore.

Three things worth checking this week

You don't need a legal team or a big IT budget to do a basic sense-check. Here's what I'd actually look at.

First, pull out your current privacy notice and find the section on third parties and data sharing. Most privacy notices for private clinics were written once, probably by whoever set up the website, and haven't been touched since. Check whether your notice accurately reflects where data goes when you correspond with GPs. If you send letters via an online dictation or correspondence platform, does that platform appear in your list of processors? It should.

Second, if you use any cloud-based practice management software, find your Data Processing Agreement with that supplier. Read the sub-processor list. This is the list of other companies your software provider is allowed to share your data with in order to deliver their service. Most clinics have never read it. Some software suppliers update it silently. Under Article 28 of UK GDPR, you're entitled to be informed of changes to sub-processors, and you should have a mechanism to object. Check whether you do.

Third, think about your correspondence workflow specifically. If you're sending GP letters through a third-party platform, NHS Mail, or a shared fax service (they still exist), write down what happens to that data after it leaves your hands. You may not be able to control what the GP practice does with it, but you should at least know what you're sending and to where.

None of this is about compliance theatre. The Federation's report points at something that will almost certainly attract ICO scrutiny at some point, and "we didn't know who owned the supplier" is not a defence that tends to go well.

The deeper issue for clinic owners

Private equity ownership of health IT infrastructure raises questions that go beyond any individual clinic's compliance position. If the companies holding GP records are optimising for revenue and exit, what does that mean for interoperability? For pricing? For the continuity of systems that clinics depend on, sometimes without realising it?

I genuinely don't know the answer to that. The Federation's report is more of a warning shot than a detailed analysis, and the consequences will play out over years, not months. What I do think is that private clinic owners who assume the NHS IT story has nothing to do with them are taking a risk. The referral pathway, the shared patient, the discharge letter, these connect your practice to that infrastructure whether you've thought about it or not.

The clinics that will handle whatever comes next are the ones who already know where their data goes. That means having a data flow map, even a rough one. It means reading your supplier agreements rather than assuming they're fine. And it means keeping your privacy notice current rather than treating it as a document you file and forget.

HealSuite keeps a record of every data processing agreement linked to a clinic's account, and flags when sub-processor lists are updated, partly because I got tired of hearing from clinic owners who'd been caught out by a silent change. But you don't need our software to do this. A spreadsheet and an hour is enough to start.

The Federation's concern is about the NHS. Your concern should be about your patients, and whether you actually know what happens to information about them once it leaves your clinic. Given what September 1st's report describes, now is a reasonable moment to find out.

Ready to modernise your practice?

Join thousands of UK healthcare professionals using HealSuite to manage their clinics.

Enquire now