NHS Blood and Transplant investigate data breach due to pager use
NHS service admits data breach due to pager use
Image source, Getty Images
NHS Blood and Transplant had been sending sensitive medical data across the unencrypted pager network
ByDan JohnsonWest of England correspondentEmma HallettWest of England producer and Chris KellyWest of England digital editor
Updated 1 hour ago
The sensitive medical data of transplant patients from across the UK was routinely sent over an unencrypted pager network, an NHS service has admitted.
A BBC investigation found NHS Blood and Transplant (NHSBT) sent the names, dates of birth and types of organs being offered or needed to members of hospital transplant teams who were using pagers, unaware they were not encrypted.
In 2019, then-Health Secretary Matt Hancock announced the NHS in England should stop using pagers by 2021, but some parts of the organisation have continued doing so.
NHSBT said it was "deeply sorry" and has reported the data breach to the Information Commissioner. It added it has now stopped sending patient data in this way.
Pagers are small battery operated radio receivers - popular in the 1980s and 1990s - that can receive short text messages, numbers to call, or alerts.
They are a one-way communication system and only able to receive messages, not send them, which was why they largely fell out of public use as more and more people started carrying mobile phones.
While NHSBT itself does not have any pagers, it was using a system that sent messages to them.
Recipients of pager messages cannot be tracked, therefore NHSBT said it was unclear whether the unencrypted information was accessed or how many people may have been affected.
Pagers were originally used because they allowed for rapid information sharing. They also work at a low frequency and are able to penetrate buildings and elevators and particularly hospitals - which can have thickened walls to protect people from X-rays and other radiation. They also have long battery lives.
The NHS is legally required to protect patients' data. The Department for Health added that where "legacy technologies" were still being used, any patient information should be "handled securely and in line with data protection requirements".
As part of our investigation, the BBC found messages that went beyond just NHSBT.
Hundreds of messages were sent across 10 days on the pager network by ambulance trusts, hospitals and fire services.
A variety of different details were transmitted, including mental health incidents, medication details, and the name of a patient trying to take their own life.
Image source, NHSBT
Head of organ transplantation at NHS Blood and Transplant, Anthony Clarkson, said the service is "deeply sorry"
NHS Blood and Transplant, which co-ordinates transplants across the country, sent messages that detailed the types of organs available, and the names, dates of birth, tissue-match scores, and immunosuppression risk factors (cRF) of the people receiving the transplants.
NHSBT acknowledged this was a data breach, after being alerted by the BBC.
The service's head of organ transplantation, Anthony Clarkson, said it had been using a system for urgent communications to transplant teams where speed can be critical. Messages were sent by email, SMS text and, until recently, to pagers.
"We accept it was a data breach," Clarkson said.
"We were surprised that these messages were not encrypted, and that vulnerability was there."
He added that NHSBT has now taken urgent measures to stop sending any messages containing sensitive information to the pager network and it has launched an internal investigation "to make sure nothing like this happens again".
Tech expert Luca Arnaboldi said pager technology - which dates back as far as the 1950s but were most commonly used from the 1980s - was "never meant for privacy"
Luca Arnaboldi, a tech expert and assistant professor at the University of Birmingham, said he was very concerned by the risks pager use could present to the NHS, adding they were "never meant for privacy".
"It broadcast messages to a large area - potentially a whole building - but even nationwide, and anybody can receive it as long as they're on the right frequency," added Arnaboldi.
"If any information on it were to be private, anybody could be listening to it. It could cause some serious security issues.
"At the worst case, there is an unauditable log of leaked information.
"What's even worse is we have no idea what somebody could do with this."
The company which owns and operates the pager network said it provides encrypted paging and secure messaging solutions, with "customers determining how those services are deployed".
It added that it has "no visibility of, or control over, the content transmitted by its customers".
It also said its terms and conditions make clear that radio signals may be intercepted, and it advises customers not to transmit sensitive or personal information over radio or public networks.
Image source, PA Media
A number of ambulance services have continued to use pagers for emergencies
Other pager users were the North West Ambulance Service (NWAS) and Northern Ireland Ambulance Service (NIAS), which sent messages with details for crews such as addresses, patient ages, and medical information.
Both services said the messages did not include patients' names, while NWAS said pagers had now been fully withdrawn and for NIAS largely withdrawn.
Health and social care in Northern Ireland is a devolved matter, and therefore the responsibility of the Department of Health NI, rather than the UK Department of Health.
The BBC has approached Department of Health NI for comment.
A spokesperson for NIAS said it "will always recognise best practice across the UK".
An Information Commissioner Office spokesperson said: "People's medical data is highly sensitive information, not only do people expect it to be handled carefully and securely, organisations also have a responsibility under the law.
"NHS Blood and Transplant reported an incident to us and we are making inquiries."
The Department for Health and Social Care said the NHS has "made progress in replacing outdated technology and is working to ensure staff have access to secure, reliable digital tools that support safe, high-quality patient care".
Get in touch
Tell us which stories we should cover in Bristol

Get our flagship newsletter with all the headlines you need to start the day. Sign up here.