NHS Blood and Transplant Admits Unencrypted Pager Breach, Halting Sensitive Data Messages
Updated
Updated · bbc.co.uk · Aug 14
NHS Blood and Transplant Admits Unencrypted Pager Breach, Halting Sensitive Data Messages
2 articles · Updated · bbc.co.uk · Aug 14
Summary
NHS Blood and Transplant said it routinely sent transplant patients’ names, dates of birth, organ details and risk data over an unencrypted pager network, then stopped the practice after a BBC investigation.
The service said speed was critical for urgent transplant coordination but it had been unaware pager messages were not encrypted; it has reported the breach to the Information Commissioner and opened an internal investigation.
Because pager recipients cannot be tracked, NHSBT said it does not know whether the data was intercepted or how many patients were affected.
Hundreds of messages sent over 10 days also exposed sensitive information from ambulance trusts, hospitals and fire services, showing some NHS bodies still rely on pagers despite a 2019 pledge to phase them out by 2021.
The Information Commissioner said it is making inquiries, while experts warned pager systems broadcast over wide areas and were never designed to protect private medical data.