The short version
- NHS Blood and Transplant confirmed it routinely transmitted unencrypted medical data via pagers, violating data protection standards.
- The breach exposed names, birth dates, and organ match details for transplant patients across the United Kingdom.
- Officials have ceased using the system for sensitive information and launched an internal review after a media investigation.
A major component of the United Kingdom’s healthcare system has acknowledged a significant failure in data security, admitting that sensitive medical records were routinely transmitted over unencrypted radio frequencies. NHS Blood and Transplant (NHSBT), the body responsible for coordinating organ transplants nationwide, confirmed that it sent private patient information to hospital teams using pager networks. This admission follows an investigation that revealed the extent of the exposure, prompting immediate changes to communication protocols within the service.
The data compromised included highly personal details such as patients’ full names, dates of birth, and specific medical metrics related to organ compatibility. Messages detailed the types of organs being offered or required, along with tissue-match scores and immunosuppression risk factors. These transmissions were directed at members of hospital transplant teams who relied on pagers for urgent alerts. The service stated it was unaware that the messages were not encrypted until the vulnerability was brought to its attention.
Pagers are one-way communication devices that have largely disappeared from public use due to the ubiquity of mobile phones. However, they remain in operation within certain sectors of the National Health Service because of their reliability. The devices operate on low-frequency radio waves, allowing signals to penetrate thick concrete walls and lead-lined elevators common in hospital environments. Their long battery life and ability to function during network outages have kept them relevant for emergency coordination despite their age.
The persistence of this technology contrasts with earlier government directives aimed at modernizing NHS communications. In 2019, then-Health Secretary Matt Hancock announced a plan to phase out pager usage in England by 2021. Despite this timeline, various parts of the organization continued to rely on the legacy system. The reliance on pagers was driven by the need for rapid information sharing in time-critical situations, such as organ transplantation, where delays can be fatal.
The scope of the breach extends beyond the transplant service. An investigation uncovered that other emergency services, including ambulance trusts and fire departments, also utilized the same unencrypted network. Over a ten-day period, hundreds of messages were broadcast containing details about mental health incidents, medication specifics, and even the names of individuals attempting suicide. This broader usage highlights a systemic issue with how sensitive data is handled across different branches of emergency response.
Technical experts have expressed concern over the inherent lack of privacy in pager technology. Luca Arnaboldi, an assistant professor at the University of Birmingham, noted that pagers were never designed for secure communication. Because they broadcast signals to a wide area, anyone with a receiver tuned to the correct frequency could potentially intercept the messages. This creates an unauditable log of leaked information, making it impossible to determine who may have accessed the data or how many people were affected.
NHSBT has reported the incident to the Information Commissioner’s Office and issued an apology for the breach. Anthony Clarkson, the head of organ transplantation at NHSBT, stated that the organization was surprised by the vulnerability. He confirmed that urgent measures have been taken to stop sending any sensitive information via the pager network. An internal investigation is underway to prevent similar lapses in the future.
The company operating the pager network stated that it offers encrypted solutions but places the responsibility for deployment on its customers. It emphasized that radio signals can be intercepted and advised against transmitting personal data over public networks. The Department for Health reiterated that any legacy technology used must handle patient information securely and in compliance with data protection laws. The incident underscores the challenges of balancing operational reliability with modern security standards in critical infrastructure.
Sources behind this briefing
Go to the original reporting
- BBC News↗NHS service admits data breach due to pager use