PulseAugur
EN
LIVE 06:03:37

NHS Copilot integration raises privacy alarms over access controls

Microsoft Copilot's integration within the NHS raises significant privacy concerns due to its lack of an independent permission model. The tool operates with the existing access rights of the signed-in user, which in the NHS context could mean widespread, outdated permissions. This, combined with clinicians already using unapproved AI tools for patient data, creates a convergence of security failures. AI

IMPACT The lack of granular access controls in AI tools like Copilot could lead to significant data privacy breaches in sensitive sectors like healthcare.

RANK_REASON The item discusses the integration of an existing AI tool (Copilot) into a specific organizational context (NHS) and highlights potential issues with its implementation, rather than a new release or fundamental research.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

NHS Copilot integration raises privacy alarms over access controls

COVERAGE [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · yeandel ·

    505,000 NHS Staff, One AI, No Locks of Its Own Copilot has no permission model of its own. It answers using whatever the signed-in user could already see, which

    505,000 NHS Staff, One AI, No Locks of Its Own Copilot has no permission model of its own. It answers using whatever the signed-in user could already see, which in a health service means decades of drifted, overshared access. Roll that out to half a million accounts, add clinicia…