Skip to content
NHS admits patient data breach...via pager

NHS admits patient data breach...via pager

Computing August 17, 2026

Transplant patients’ sensitive medical information was routinely transmitted through an unencrypted pager network, NHS Blood and Transplant (NHSBT) has admitted.

The information included patients' names, dates of birth, the organs they needed and tissue-match scores.

It is possible that unintended recipients saw the messages, but that is difficult to determine due to the way pagers operate.

The potential breach was uncovered by a BBC investigation , which found that hospital transplant teams had received the information through pagers without being aware the messages were not encrypted.

NHSBT says it has reported the incident to the Information Commissioner's Office (ICO) and has stopped sending patient information through the pager network.

NHSBT coordinates organ transplants across the country and relies on various communication systems to quickly alert transplant teams when organs become available.

Head of organ transplantation Anthony Clarkson said the service had used email, SMS and, until recently, pagers because information sometimes needed to be shared quickly.

"We were surprised that these messages were not encrypted, and that vulnerability was there," he said.

NHSBT said it had taken urgent steps to prevent sensitive information being sent through the pager system and had launched an internal investigation.

Because pager messages cannot be traced to individual recipients, NHSBT could not establish whether the information had been accessed by anyone else or determine exactly how many people could have been affected.

Pagers are simple radio receivers that can deliver short messages or alerts.

While widespread in the 80s and 90s, their usage shrank after the widespread adoption of mobile phones. However, their reliable service, long battery life and ability to operate through thick walls and in lifts means they are still used in some applications.

The issue extended beyond NHSBT, the BBC found.

Hospitals, ambulance trusts, and fire services sent hundreds of messages over the network during a 10-day period.

Some contained information mental health incidents, medication and patients in medical emergencies.

The Northern Ireland Ambulance Service (NIAS) and North West Ambulance Service (NWAS) used the network to provide crews with information such as addresses, patients' ages and medical details.

Both services said patient names were not included. NWAS said pagers had now been completely withdrawn, while NIAS said they had been largely phased out.

The company that operates the pager network said it offers encrypted paging and secure messaging services, but customers are responsible for how they use them. It said it cannot see or control the content sent by customers. Its terms and conditions also warn that radio signals may be intercepted and advise against sending sensitive information over radio or public networks.

Pagers have remained in use despite a 2019 announcement by then-Health Secretary Matt Hancock that the NHS in England should phase them out by 2021.

The Department of Health and Social Care said the NHS had made progress in replacing outdated systems and was working to provide staff with secure and reliable digital tools.

The ICO said medical information was "highly sensitive" and that organisations had a legal responsibility to protect it.

NHSBT said its internal investigation would examine how the messages came to be sent without encryption and what measures were needed to prevent a similar incident happening again.

Extracted Entities

Attack Types (1)

Industries (1)

Platforms (2)