NHS service admits data breach due to pager use
The medical data of transplant patients from across the UK was sent over an unencrypted pager network.
The sensitive medical data of transplant patients across the UK was routinely transmitted over an unencrypted pager network, NHS Blood and Transplant (NHSBT) has admitted. A BBC investigation revealed that names, dates of birth, and types of organs were sent to transplant team members using pagers, unaware that the information was not encrypted.
In 2019, then-Health Secretary Matt Hancock had announced the NHS in England should stop using pagers by 2021, yet some parts of the organization continued to do so. NHSBT expressed deep regret and reported the data breach to the Information Commissioner. The service has since stopped sending patient data via this method. Pagers, once popular in the 1980s and 1990s, are now largely obsolete due to the widespread use of mobile phones.
NHSBT does not own any pagers but utilized a system that sent messages to them. Recipients of pager messages cannot be identified, making it unclear whether the unencrypted information was accessed or affected how many individuals. While originally used for rapid information sharing, pagers now pose significant security risks due to their lack of encryption and ability to broadcast messages to a wide area.
The NHS is legally obligated to protect patient data, and the Department for Health emphasized that any legacy technology used should handle information securely and in compliance with data protection regulations.
Written by urgent.news from BBC News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.