NHS Blood and Transplant (NHSBT) has confirmed it is investigating a data breach involving the transmission of sensitive medical information over an unencrypted pager network. The service routinely sent patient names, dates of birth, and details regarding organ availability or requirements to hospital transplant teams using pagers that were not secured with encryption.
While NHSBT does not directly own pagers, it utilized a system that transmitted messages to them. These devices were historically favored for their ability to function at low frequencies, allowing them to penetrate thick hospital walls and elevators where mobile phone signals often struggle. Additionally, they were valued for their long battery life and rapid information-sharing capabilities. However, because they function as a one-way communication system, it is currently impossible for NHSBT to track who received the messages or whether the unencrypted data was accessed by unauthorized parties. Consequently, the organization has stated it remains unclear how many patients were affected by the breach.
This incident comes despite a 2019 directive that the NHS in England should phase out the use of pagers by 2021. Despite this mandate, some areas of the organization continued to rely on the technology. In response to the findings, NHSBT stated it is "deeply sorry" for the oversight and has reported the matter to the Information Commissioner. The organization confirmed that it has now ceased the practice of sending patient data via these unencrypted systems.
Pagers were originally used because they allowed for rapid information sharing. They also work at a low frequency and are able to penetrate buildings and elevators and particularly hospitals – which can have thickened walls to protect people from X-rays and other radiation. They also have long battery lives.
'Swimming was not in my community's vocabulary'





