TL;DR
Two NHS practitioners have set out what data residency actually costs the people signing for it. General practice indemnity covers a rogue individual, not a systemic failure — so a partner whose supplier mishandles data abroad is exposed personally, without limit. One trust has responded by refusing to hold a sales conversation until a vendor maps every processing step.
The gap nobody underwrites
Dr William Lumb, a Sedbergh GP and chief clinical information officer for the primary care collaborative at Morecambe Bay, puts it bluntly: he is personally liable, with no ceiling. The cover available to general practice was designed for a rogue individual inside the practice, not for a failure originating somewhere in a supply chain. Ownership of NHS data is itself unsettled in statute, resting on case law that dates from paper records.
His second point cuts against the reflex response. Information governance, he argues, is too often the reason given for not adopting something, when in his experience no such barrier is genuinely immovable. Cumbria proved it a decade ago: GP records reached social care systems safely, once the teams had pinned down exactly where the data physically lived.
What AI changed, and what it did not
The AI technical lead for University Hospitals of North Midlands, Dan Tudor, is careful that the jurisdictional risk long predates AI: the American statutes in play date from 2001 and 2018, and Britain and its allies make equivalent demands of one another. What AI adds is scale and opacity. A record can now cross a border mid-pipeline, be handled by a model running on hardware nobody local controls, and come back with no account of what touched it.
His trust’s answer is what it calls “evidence-led assurance”: suppliers must show how the model works, where processing happens at each stage, and which legal process would apply to an access request — all before any commercial discussion starts. Trusts should also pin down who owns the input, the model and the output as three separate questions, since some suppliers merely host models built by others and hold no rights over them.
Looking forward
Lumb’s warning against the “bucket model” — one AI fixing problems across a whole health system — reads as a corrective to a busy year. NHS scribes have already been found getting diagnoses wrong, even as ChatGPT gained access to patient records inside Epic. Narrow, well-defined tasks are where the evidence sits. The procurement question to borrow is Tudor’s: not whether a supplier is compliant, but whether it can draw you the map.