NHS admits data breach by sending patient data via pagers
NHS admits data breach by sending patient data via pagers

The NHS has admitted a data breach by sending patients’ personal information over pager devices. A BBC investigation found sensitive medical data of transplant patients was routinely sent over an unencrypted pager network. The information included the names, dates of birth and types of organs being offered or needed.

Outdated technology still in use

The small battery operated radio receivers can receive short messages and numbers to call back and were popular in the 80s. In almost all other industries they have become obsolete but a lack of investment in NHS tech infrastructure means they are still used in some hospitals. Their messages can in theory be intercepted if a device tuned into the right frequency - although there is no evidence this data was obtained by anyone other than NHS teams.

Expert warns of security risks

Luca Arnaboldi, a tech expert and assistant professor at the University of Birmingham, told the BBC: "It broadcast messages to a large area, potentially a whole building, but even nationwide, and anybody can receive it as long as they're on the right frequency. If any information on it were to be private, anybody could be listening to it. It could cause some serious security issues. At the worst case, there is an unauditable log of leaked information… we have no idea what somebody could do with this."

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

NHS Blood and Transplant responds

NHS Blood and Transplant (NHSBT) sent messages that detailed the types of organs available, and the names, dates of birth, tissue-match scores, and immunosuppression risk factors of the people receiving the transplants. Its boss said it was "deeply sorry" and has reported the data breach to the Information Commissioner. Anthony Clarkson, NHSBT director of organ and tissue donation and transplantation, said: "We accept it was a data breach. We were surprised that these messages were not encrypted, and that vulnerability was there."

The North West Ambulance Service (NWAS) was also found to be using pagers for messages with details for crews such as addresses, patient ages, and medical information. It messages did not include patient names and that pagers had now been fully withdrawn.

Calls to phase out pagers

Former Health Secretary Matt Hancock announced in 2019 that the NHS in England should stop using outdated devices such as pagers by 2021 but some parts of the health service have continued doing so. The Department for Health and Social Care said that where "legacy technologies" were still being used in the NHS any patient information should be "handled securely and in line with data protection requirements".

An NHSBT spokesperson said: "Organ transplantation is a time-critical service where rapid communication is essential to save lives. To inform hospitals about an opportunity of a transplant for a patient on the waiting list, we send an urgent message. This is sent via a system to a hospital transplant team who receive these messages via email, SMS text and, until recently, pagers. We have learnt, when the system sent a message to a pager, the data was not encrypted. We took immediate action to stop sending patient identifiable information. We reported it to the Information Commissioner and our regulators, and are carrying out an internal investigation. We are deeply sorry for the concern this will cause patients and their families. Protecting their information is extremely important to us and we are committed to ensuring operational needs are balanced with the highest standards of information governance and data protection."

Pickt after-article banner — collaborative shopping lists app with family illustration