NHS admits transplant patient data was broadcast unencrypted over pagers for years

Started by Ederson, Aug 15, 2026, 02:46 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: NHS admits transplant patient data was broadcast unencrypted over pagers for years   Views(Read 70 times)

Ederson

A BBC investigation has found that NHS Blood and Transplant routinely sent sensitive medical information about transplant patients over an unencrypted pager network, and the service has now formally admitted this constitutes a data breach and reported it to the Information Commissioner

The details involved are genuinely sensitive, names, dates of birth, the types of organs being offered or needed, tissue match scores and immunosuppression risk factors were all sent to hospital transplant teams via a system that could also route messages to pagers, and NHSBT says it did not realise those pager transmissions were unencrypted

What makes this particularly alarming from a security standpoint is how pagers actually work, they broadcast over open radio frequency to a wide area, potentially an entire building or even nationwide, and anyone with basic commercially available receiving equipment on the right frequency could intercept and read the messages, with no audit trail of who might have been listening

This is not a new problem either, the government told the NHS to phase out pagers entirely by 2021 after the technology was flagged as outdated and insecure, yet reporting shows roughly 130,000 pagers were still in use across the NHS as of recent counts, some ten percent of the world's remaining pager stock, and this specific transplant use case slipped through despite years of prior warnings

NHSBT's defence is that organ transplantation is genuinely time critical, when an organ becomes available the team needs to reach hospital staff immediately, and pagers have historically been valued for exactly that kind of urgent one way broadcast reliability, but that operational justification does not really excuse transmitting identifiable patient data over an unsecured channel for this long without anyone catching it

NHSBT says it has now stopped sending patient identifiable information via pager and is carrying out an internal investigation, but the bigger story here is really about chronic underinvestment in NHS communication infrastructure, this is at least the second time pager related data exposure has made headlines and it clearly will not be the last as long as legacy hardware keeps getting patched over rather than properly replaced


Thomas_69

Anyone with a cheap radio receiver could have been listening to organ transplant details this whole time, that is genuinely unsettling

RobVanDam

Pagers being one way broadcast devices makes this so much worse than a typical data breach, there is no way to know who actually intercepted anything

IronSpectre88

Organ transplant coordination is about as high stakes as healthcare data gets, this really should have had encryption as a baseline requirement from day one

CMPunk02

The government told them to stop using pagers back in 2021, four years of ignoring that warning is not a small oversight

KaiHeck

Reliability doesnt matter much if the tradeoff is broadcasting patient identifiable data in the clear to anyone nearby

Loki Daemon

Wonder how many other legacy systems across the NHS have similar unencrypted quirks nobody has tested yet

Related Topics (1)

Save money on everyday spending Free cashback on thousands of retailers
View offer