Barts Health NHS Trust runs one of London’s largest hospital groups. Its public internet footprint is also the most tangled of any trust in England, with 304 separate DNS records that point to UK-sovereign infrastructure and three US hyperscalers. Computer Weekly’s analysis of those records finds 113 pointing to US-controlled services and 135 to UK-held ones.
Barts is the extreme, but not an outlier. Of the 213 NHS trusts and foundation trusts listed in the NHS England provider directory, 165 (77%) have at least one connection to Amazon Web Services (AWS), Google Cloud or Microsoft. Meanwhile, 132 (62%) route their email and identity through Microsoft 365. Microsoft, in other words, is not one supplier among many for the English NHS. It is a default.
This article – the second in a series – maps which outside companies NHS trusts actually connect to, by examining public DNS records. It finds a service that has concentrated email and much of its infrastructure on a single US hyperscaler – and, in doing so, has entangled routine patient data flows across two jurisdictions.
While the UK government’s “cloud-first” policy was intended to use public cloud platforms before considering other options, it was also meant to avoid supplier lock-in.
By mapping the digital perimeter of NHS trusts, we can see a clear pattern of dominance by US providers.
The Microsoft default
The concentration is starkest in email. Nearly two-thirds (62%) of trusts route their mail through Microsoft’s servers, while 8% use Google Workspace and 30% run a custom or hybrid setup. Measured by routable infrastructure – the DNS records that actually point to a server, rather than the text notes used for email authentication – Microsoft accounts for 1,889 records, against 229 for Amazon and 24 for Google.
The comparison with Google and Apple is instructive. Google’s presence in the NHS is mostly email: 49 of its 73 records are SPF (Sender Policy Framework) authorisations, the text notes that say who may send a trust’s email, rather than hosting. Apple, which appears in a raw count of the data, hosts nothing – all 73 of its records are verification tokens for device management, not infrastructure.
Microsoft, by contrast, dominates both. It holds 1,889 routable records and a further 220 SPF records, making its presence roughly eight times that of Amazon and 79 times that of Google on the infrastructure the NHS’s systems depend on.
The sovereignty tangle
The finding that matters most is not the size of Microsoft’s share but the shape of it. Three-quarters of trusts – 162 of 213 – sit in what we could call a “tangled hybrid” posture: dependent simultaneously on UK-sovereign infrastructure and on US-hosted services that fall within the reach of the US Cloud Act. Only 48 trusts are cleanly sovereign, while three are wholly US-dependent.
For a health service that holds some of the most sensitive personal data of any UK institution, that tangle is not an abstraction. Every trust that routes patient email through a US hyperscaler creates a data flow that can, in principle, be the subject of a US court disclosure demand. The NHS has not, on this evidence, made a conscious decision to avoid that position; it has drifted into it.
A diverse, long tail
Dependence does not stop at the big three. Beyond Microsoft, Amazon and Google sits a long tail of non-hyperscaler suppliers, most of them UK or European. The single largest is Enflow, a Dutch cloud host, with 218 records, followed by managed WordPress provider WP Engine with 82, security supplier Imperva with 71, and BT with 47. UK cloud and hosting firms such as eCloud and UKFast sit further down the list.
The NHS also retains a meaningful amount of its own infrastructure. The analysis attributes 1,138 records (8.9% of the routable total) to NHS-owned ranges, led by a single network, UKNHS-D2U0B, which has 796 records. That netname belongs to NHS England itself and is the largest single piece of genuinely on-premise estate found in the analysis.
The contrast between the two extremes makes the point. Barts Health – a major London acute trust – sprawls across 304 records and four external suppliers. Alder Hey, a major children’s hospital in Liverpool, sits at the other end: 10 records, no external supplier at all, every one of them NHS or local. A trust of that size with a footprint that clean is rare, but it shows that a different configuration is technically possible.
The methodology behind the data
Computer Weekly analysed the public DNS footprint of 213 NHS trusts and foundation trusts listed in the NHS England provider directory on 1 September 2026. For each organisation it collected the published website domain and then interrogated its public DNS – root records, a sweep of 220 common subdomains and passive Certificate Transparency logs – to produce 12,829 individual DNS records. Each record is one “node” in the analysis.
It then mapped each IP address to its registered owner through RDAP, the registration-data protocol used by the regional internet registries, and classified each record as a hyperscaler (Microsoft, Amazon or Google), another cloud/CDN/SaaS provider, a third-party host or ISP, or NHS-owned infrastructure.
One limitation matters. TXT records – the text notes used for email authentication and domain verification – are not routing records They carry text rather than a destination, so they cannot resolve to an owner. Of the 12,829 records, 6,937 are TXT records, and these sit outside the infrastructure figures.
A small number of records could not be traced to an owner. A few points to reserved or inactive hostnames (such as null-MX and “.invalid” placeholders), and a handful of addresses could not be queried because the internet registries rate-limit automated lookups. These are reported as unattributed and excluded from the supplier figures. The hyperscaler figures are therefore a lower bound: the unresolved records would likely add to them.
The pipeline runs in four stages: Enumerate the published domain of each trust; sweep its public DNS – A, AAAA, MX, TXT and NS records, plus a 220-strong subdomain dictionary and Certificate Transparency logs; resolve every address to its owner through RDAP; and classify each record against a supplier and a jurisdiction.
The NHS has no obvious exit from a single-supplier default. The contracts that keep it there renew on a rolling basis, through a procurement system under growing pressure. The analysis does not suggest the NHS chose Microsoft badly. There’s no evidence for how services were chosen in the data, but if the NHS is anything like other parts of the public sector, we might find a lack of competition here too.
S 004