NHS Blood and Transplant has admitted to a significant data breach after routinely sending sensitive patient information over an unencrypted pager network to hospital transplant teams nationwide.
Key Points
- NHS Blood and Transplant (NHSBT) transmitted patient names, birth dates, and organ transplant details via unencrypted pager messages.
- The practice continued despite a 2019 government mandate from then-Health Secretary Matt Hancock to phase out pager use across the NHS by 2021.
- Pager signals are broadcast over radio frequencies, making them susceptible to interception by anyone with the correct equipment.
- NHSBT has reported the breach to the Information Commissioner’s Office and confirmed that the transmission of sensitive data via pagers has ceased.
- A BBC investigation revealed that other services, including ambulance trusts and fire departments, also used the network to transmit sensitive medical and mental health information.