Computing NHS Data Breach: Sensitive Patient Information Exposed via Unencrypted Pagers
Article Content
- •NHSBT admitted to transmitting sensitive patient data over unencrypted pagers.
- •The breach included names, dates of birth, and organ information of transplant patients.
- •NHSBT has reported the incident to the ICO and stopped using pagers for patient data.
The NHS Blood and Transplant (NHSBT) has admitted to a data breach involving the unencrypted transmission of sensitive medical data for transplant patients over a pager network. This breach, uncovered by a BBC investigation, included patients' names, dates of birth, organ requirements, and tissue-match scores. Although NHSBT has reported the incident to the Information Commissioner's Office (ICO) and ceased using the pager system for patient data, the extent of the exposure remains unclear due to the nature of pagers, which cannot track recipients. The breach also affected other emergency services, with hundreds of messages sent over a 10-day period containing various sensitive information. NHSBT's head of organ transplantation acknowledged the vulnerability and stated that urgent measures have been taken to prevent future incidents.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track NHS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…