NHS Blood and Transplant admits patient data was sent unencrypted via pagers
NHS Blood and Transplant revealed that sensitive transplant patient information was routinely transmitted over an unencrypted pager network, constituting a data breach.
An inquiry by one outlet found that NHS Blood and Transplant routinely dispatched confidential transplant patient data—including names, dates of birth and organ information—through an unencrypted pager system used by hospital teams. The organization expressed deep regret, notified the Information Commissioner and immediately stopped sending such information via pagers. Although the former Health Secretary announced a plan to eliminate pager use by 2021, parts of the NHS continue to depend on the outdated technology.
The breach was discovered after the service was alerted by one outlet, and the head of organ transplantation, Anthony Clarkson, said the vulnerability was unexpected. Experts warned that pagers, designed for rapid one-way alerts, are not suited for protecting private health data. The investigation also identified similar unsecured messages from ambulance and fire services, highlighting broader risks across emergency responders.
Why it matters
Patient privacy was compromised because a national health service used outdated, unencrypted paging technology.
In this story
