NHS Blood and Transplant admits patient data breach via unencrypted pagers, ICO investigates

Two regional ambulance services that used pagers reported different decommissioning statuses: the North West Ambulance Service has fully withdrawn pagers, while the Northern Ireland Ambulance Service said they have been largely withdrawn, illustrating uneven rollout of legacy-system phaseouts.
BBC reporting indicates pager messages could include not only names and birth dates but also incident addresses, patient ages, and other specific medical details, widening the scope of data exposed.
NHS Blood and Transplant stated it does not own pagers; the breach involved a system that sent messages to hospital transplant teams, suggesting the vulnerability lay in the messaging pipeline rather than device ownership alone.
Pagers transmit over low-frequency, unencrypted radio channels and lack the encryption and security controls of modern digital messaging, making interception possible with basic radio scanning equipment.
NHS Blood and Transplant has admitted it routinely sent sensitive transplant patient data — including names, dates of birth, and organ details — over an unencrypted pager network, BBC revealed. The health body has now stopped sending patient data this way and reported the incident to the Information Commissioner's Office, which is actively investigating.
The breach is significant because pagers transmit over low-frequency radio channels with no encryption. Anyone with basic radio scanning equipment could have intercepted the messages, according to BBC.
The exposed data went far beyond names and birthdates. BBC reported that pager messages could include incident addresses, patient ages, and specific medical details linked to organ transplants. NHS Blood and Transplant coordinates organ transplants across the UK, meaning the data involved some of the most sensitive health records in the country.
NHSBT stressed that it does not own the pagers involved. The breach lay in the messaging pipeline used to contact hospital transplant teams, not in the devices themselves. That distinction matters — it means the vulnerability was baked into how information was sent, not just what equipment received it, according to Digit.
Pagers are one-way devices. They receive messages but cannot confirm who is reading them. They also use unencrypted radio signals, meaning no password, no login, and no way to verify the recipient. Modern digital messaging tools use end-to-end encryption. Pagers have none of that, Mirror reported.
Interception requires no sophisticated hacking. A cheap radio scanner — available to the public — is enough to pick up pager signals. Security experts have long flagged this risk, but parts of the NHS continued using the technology well past the government's 2021 guidance to move away from pagers, according to BBC.
The phaseout of pagers across UK emergency services has been uneven. The North West Ambulance Service fully withdrew pagers. The Northern Ireland Ambulance Service said pagers have been "largely" withdrawn — but not entirely. That gap shows how hard it is to retire old systems, even when clear guidance exists, according to BBC.
The government told NHS organisations to stop using pagers by 2021. Some parts of the health service kept using them anyway. Decommissioning old infrastructure takes time and money, and in a stretched health service, legacy tech often stays longer than it should, Digit noted.
The Information Commissioner's Office is now actively investigating the breach. The ICO enforces UK data protection law and can issue fines for serious violations. Health data sits in the highest category of sensitivity under that law, meaning NHSBT faces serious scrutiny over how long this practice continued, according to Mirror.
NHSBT confirmed it has stopped transmitting patient data via pager and has self-reported to the ICO. The admission follows the BBC investigation going public, raising questions about whether the breach would have been addressed without outside pressure. The ICO has not yet announced any findings, Digit reported.
Publishers
10
Articles
7
Reach
17