All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

NHS service admits data breach due to pager use

Created at 14 Aug · 5:46 AM1 source↑ Market-relevant
IN SHORT

NHS Blood and Transplant (NHSBT) has admitted to a data breach after sensitive medical information of UK transplant patients was routinely sent over an unencrypted pager network. The service has reported the incident and stopped the practice.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

10 daysduration of messages sent across pager network

Who's Involved

NHS Blood and Transplant
NHS service that sent sensitive patient data over unencrypted pagers
Matt Hancock
Former Health Secretary who announced a 2021 pager phase-out
Anthony Clarkson
Head of organ transplantation at NHS Blood and Transplant
Luca Arnaboldi
Tech expert and assistant professor at the University of Birmingham
Information Commissioner
Regulator investigating the data breach
North West Ambulance Service
Ambulance trust that used pagers for emergency messages
Northern Ireland Ambulance Service
Ambulance trust that used pagers for emergency messages

↳ Why This Matters

The incident highlights a critical failure in data security within the NHS, exposing sensitive patient information due to the continued use of outdated and unencrypted technology, potentially undermining patient trust and violating data protection laws.

Key facts

  • NHS Blood and Transplant (NHSBT) sent sensitive medical data, including names and dates of birth, over an unencrypted pager network.
  • The data pertained to UK transplant patients, detailing organs being offered or needed.
  • The use of pagers for this data continued despite a 2019 directive to phase them out by 2021.
  • NHSBT has acknowledged the incident as a data breach, reported it to the Information Commissioner, and ceased the practice.
  • Other NHS services, including ambulance trusts and fire services, also utilized the pager network for transmitting various sensitive details.

NHS Blood and Transplant (NHSBT) has admitted to a significant data breach involving the transmission of sensitive medical information of UK transplant patients over an unencrypted pager network. The data, which included patient names, dates of birth, and details about organs being offered or needed, was sent to hospital transplant teams using pagers.

This practice continued despite a 2019 announcement by then-Health Secretary Matt Hancock that NHS services in England should stop using pagers by 2021. NHSBT stated it was "deeply sorry" for the breach and has reported the incident to the Information Commissioner, confirming that it has now ceased sending patient data in this manner.

Investigations revealed that the use of pagers for sensitive data was not isolated to NHSBT. Messages containing various details, including mental health incidents and medication information, were sent by ambulance trusts and fire services over the pager network. While NHSBT does not use pagers itself, it utilized a system that sent messages to them. The company operating the pager network indicated that its terms and conditions advise customers against transmitting sensitive information over radio or public networks, as signals may be intercepted.

Tech experts expressed concern over the inherent privacy risks associated with pager technology, noting they were "never meant for privacy" and could broadcast messages widely, potentially allowing unauthorized reception. The Department for Health and Social Care acknowledged that while progress has been made in replacing outdated technology, efforts are ongoing to ensure staff have secure digital tools.

Frequently asked questions

The compromised data included patient names, dates of birth, types of organs being offered or needed, tissue-match scores, and immunosuppression risk factors.

Pagers were used for urgent communications where speed is critical, and they can penetrate buildings effectively. However, they are an outdated technology not designed for privacy.

NHSBT has apologized, reported the breach to the Information Commissioner, stopped sending sensitive data via pagers, and launched an internal investigation.

Yes, other ambulance trusts and fire services were found to have used the pager network for transmitting various sensitive details.

What Happens Next

01NHSBT is conducting an internal investigation to prevent future occurrences.
02The Information Commissioner's Office is making inquiries into the reported incident.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

NHS Blood and Transplant (NHSBT) sent sensitive medical data over an unencrypted pager network.
The data included patient names, dates of birth, and organ details.
The practice continued despite a 2019 announcement to phase out pagers by 2021.
NHSBT has apologized, reported the breach to the Information Commissioner, and stopped sending data via pagers.
Other ambulance trusts and fire services also used the pager network for sensitive information.
The pager network operator stated customers are responsible for how services are deployed and advised against transmitting sensitive data.

Sources

T1
NHS service admits data breach due to pager useBBC News

Related Stories

EU watchdog warns of privacy risks in Europol data plan
13 Aug · 9:56 AM
US to allow private firms to conduct offensive cyberattacks
13 Aug · 2:32 PM
City firms tighten transgender bathroom access policies after watchdog guidance
14 Aug · 4:11 AM
BAE Systems to pay $36m penalty for US arms export rule violations
13 Aug · 5:50 PM
US restricts funding for professor over China programs
13 Aug · 6:31 PM