An open letter asking NHS England to keep its code open.
We believe that this document is fully human-written.
Hacker News Article AI Analysis
Content Label
Human
AI Generated
0%
Human
100%
Window 1 - Human
An open letterasking NHS Englandto keep its code open
Code paid for with public money should be open to the public. This
principle is enshrined in the UK Government Design Principles and
the NHS Service Standard. It is now being walked back. We are
signing this to restate the case.
Add your signature →
Published1 May 2026
StatusOpen for signatures
Signatures9 signatures so far
Andrew NesbittSoftware Developer and Researcher (Ecosyste.ms)Daniel RoeCore team lead (Nuxt)Heidar BernhardssonMiranda HeathResearcher (University of Edinburgh)Misha GorodnitzkyTechnical ArchitectMarcus BawGP, Clinical Informatician and Developer (Baw Medical, RCPCH, openEHR International)Paul Robert LloydInteraction designerTheodor VararuSoftware EngineerVlad-Stefan HarbuzMaintainer (Open Source Pledge)
Statement
We disagree with the NHS technical leadership’s decision to
hide the source code of all of their repositories.
Making code open source requires more work than keeping it closed.
That hard work is the point.
It requires a higher bar of quality. It requires processes to
proactively find, fix, and monitor for vulnerabilities. It
requires identifying risk, and putting barriers in place to
contain any damage when things go wrong.
But it works like the human immune system: being exposed to
threats hardens the attack surface.
Closed source allows that work to be skipped. It substitutes
obscurity for depth, and obscurity buys you precious little
when a sufficiently motivated attacker is involved.
Warning
We call on NHS England to withdraw the SDLC-8 red line and
reaffirm its commitment to the NHS Service Standard Principle
12: “Make new source code open.”
If you agree, sign your name using the form below.
Submissions are reviewed by hand and you’ll appear on the
page once approved.
Window 2 - Human
References
NHS Goes To War Against Open Source
NHS England rushes to hide software over AI hacking fears
NHS Service Standard — Principle 12: Make new source
code open
NHS England quietly removes open source policy web pages
(Digital Health)
Don’t be afraid to code in the open: how to do it
securely (GOV.UK)
Does Mythos mean shutting down your open source repos?
(shkspr.mobi)
Discourse is not going closed source (Discourse)