The numbers tell a story that keeps NHS researchers up at night: thousands of GP practices holding some of the richest patient data in the world, billions in public funding committed to clinical trials, and recruitment rates that remain stubbornly slow. The missing link? Getting those practices comfortable enough to actually help identify eligible patients.
A London startup called London Quantum Group thinks it has an answer—one built on encrypted computation rather than the usual promises of better data governance policies. Its recently launched platform, Provenance, is designed to let primary care practices surface trial-eligible patients from their electronic health records without those records ever leaving the building or being decrypted. No data extraction, the company says. No new workflows for already-overworked clinicians. And crucially, a "structural guarantee" that the company itself can't peek at the data, even if it wanted to.
It's a deliberately narrow pitch, perhaps narrower than venture investors usually like. But in the thicket of NHS information governance, narrow might be exactly what's needed.
A Problem Hiding in Plain Sight
The tension in UK clinical trial recruitment has always been a bit absurd. GP records contain the most current, detailed clinical information on patients—medication histories, lab results, diagnoses that haven't yet made it into secondary care systems. Research networks and pharmaceutical sponsors desperately want access to that data to find trial candidates. And yet, between patient privacy concerns, information governance frameworks that often feel designed for a pre-digital era, and the sheer operational burden on practices, most of that potential sits untapped.
Existing tools do exist. EMIS Recruit, embedded within the widely used EMIS-X system, already offers in-system patient identification, though without the encryption-based approach that Provenance claims. But Provenance positions itself as something different—a layer that works across platforms and runs eligibility searches over encrypted data. The company aligns its approach with the NHS's evolving Secure Data Environment model, which emphasizes controlled access over wholesale data sharing.
Whether that distinction matters in practice remains to be seen.
The Cryptography Question

Here's where things get interesting, and a bit murky. London Quantum Group's website talks about "advanced encryption" and claims alignment with ICO and ISO standards. But it stops short of specifying the actual technique: fully homomorphic encryption? Secure multi-party computation? Trusted execution environments? Some bespoke hybrid?
That vagueness stands out, especially in a sector where competitors like Duality Technologies, Tune Insight, and Enveil have turned their "privacy-enhancing technologies" stacks into marketing narratives. For a company that chose the word "Quantum" in its name, the lack of technical detail feels deliberate—whether that's strategic positioning or something still being worked out is hard to say from the outside.
What the company does emphasize is the value proposition for GP practices: identify patients, connect them to research networks and delivery sites, generate new revenue streams. All without crossing governance red lines or adding to administrative burdens that are already breaking the system.
Sebastian Kot, the founder, describes London Quantum Group as a "commercial research lab focused on rebuilding the foundations of AI using number theory" with applications in healthcare and law. He's been visible in UK quantum and startup circles—participating in accelerators, presenting at Revolut's headquarters earlier this year. But visibility and deployment are different animals, particularly in the NHS.
Timing, Policy, and the Quantum Moment
The timing is not accidental. The UK government has committed £2 billion to quantum initiatives, and NHS England has been methodically shifting away from legacy "data sharing" models toward controlled access through Secure Data Environments and Trusted Research Environments like OpenSAFELY. The latter runs analyses inside EHR vendor data centers without exposing raw patient records—a model that has gained traction precisely because it sidesteps the governance nightmare of centralized data lakes.
A 2021 proof-of-concept from NHS Digital and Privitar demonstrated partially homomorphic encryption for privacy-preserving linkage of patient identifiers, signaling receptiveness to cryptographic techniques. But practical deployment of fully homomorphic encryption or similar compute-on-encrypted-data methods in actual clinical workflows? Still vanishingly rare.
Company filings show a share allotment in May, indicating potential financing activity, though no specific amount or investor details have been confirmed. The LinkedIn presence lists between 2 and 10 employees, with offices in London and Troy, New York—a geographic split that raises its own questions about where the technical work is actually happening.
The Elephant in the Integration Room

There's a conspicuous silence on the company's website: no mentions of integration partners. No EMIS, no TPP SystmOne, no Epic. No formal relationships listed with NHS research networks like the NIHR Clinical Research Network or the Primary Care Research Alliance.
For anyone familiar with health IT procurement in the UK, that silence is loud. The existing EHR vendors have spent years, sometimes decades, embedding themselves into practice workflows and meeting the exacting standards of GP Connect's information governance principles. An external layer, even one promising encryption and compliance, faces a steep climb to prove it can slot into that ecosystem without creating new friction for practice staff who are already stretched impossibly thin.
The question isn't just whether the encryption works. It's whether it works inside the messy, legacy-laden, politically fraught reality of NHS digital infrastructure. And whether practices—who've watched data-sharing initiatives blow up spectacularly in the past, most notably the care.data debacle—will trust it.
The Unlock, If It Works

London Quantum Group's fundamental bet is simple: there's a latent market of GP practices that have the data researchers need but lack the governance comfort or operational capacity to share it. Privacy-preserving computation, if it delivers on its promise, could unlock that market.
The company is offering demos now. What happens next depends on navigating the NHS procurement labyrinth, proving the technology scales, and—perhaps most crucially—convincing practices that encrypted computation is actually simpler than the status quo, not just a more sophisticated version of the same headache.
If they pull it off, they'll be riding two waves at once: the £2 billion quantum technology push and the desperate need for better clinical trial recruitment infrastructure. That's the kind of tailwind most startups only dream about.
Whether the technology can actually catch it is the part we're all about to find out.
