NHS admits transplant patient data sent over unencrypted pagers

Transplant patients and other vulnerable individuals had highly sensitive medical information including mental health crises and immunosuppression data exposed without their knowledge or consent.
Pagers were never meant for privacy. Anybody could be listening.
A technology expert explains why using unencrypted pagers for sensitive medical data posed a fundamental security risk.
Mark

Why would a modern health service still be using pagers at all in 2026?

Mimi

Because they work in places where other signals fail. Hospital walls are thick. Pagers penetrate them. And they're fast—when you need to tell someone an organ is available, you need them to know immediately. But speed and reliability came at the cost of security.

Mark

So NHSBT knew they were using pagers, but didn't know the messages weren't encrypted?

Mimi

That's what they're saying. They thought the system was secure. They were wrong. And because pagers are one-way—you can only receive, not send—there's no way to audit who got the messages or when.

Mark

Could someone have been listening the whole time?

Mimi

Yes. Anyone with a pager on the right frequency could have received those messages. Names, dates of birth, organ types, tissue-match scores. All of it. And we'd never know.

Mark

This wasn't just transplant data, though.

Mimi

No. Ambulance services were using the same network. Fire services too. Mental health incidents, medication details, even the name of someone in crisis. It was a much wider vulnerability than just one department.

Mark

What happens now?

Mimi

NHSBT has stopped sending patient data via pagers and launched an investigation. The Information Commissioner is looking into it. But the damage—if there was damage—is already done. You can't unbroadcast information.

  • Transplant patients' most intimate medical details — organ types, tissue scores, immunosuppression risks — were broadcast in plain text over pager frequencies accessible to anyone with the right receiver.
  • The exposure extended far beyond transplant coordination: mental health crises, medication details, and the names of patients in suicidal distress crossed the same open network from ambulance trusts, hospitals, and fire services.
  • A 2019 government directive to phase out NHS pagers by 2021 was never enforced, leaving a known vulnerability to quietly persist for years while sensitive data continued to flow unprotected.
  • Because pagers are one-way broadcast devices with no auditable trail, neither NHSBT nor any affected organisation can determine whether the data was intercepted, or by whom — the full scope of exposure may never be known.
  • NHSBT has halted pager transmissions and reported the breach to the Information Commissioner's Office, while the network operator noted its own terms warned against transmitting sensitive data over radio — a warning that went unheeded.

In the invisible architecture of modern medicine, where seconds determine whether organs reach their recipients, NHS Blood and Transplant quietly broadcast some of the most intimate details of human vulnerability — names, organs, immunosuppression risks — across an open radio frequency that anyone could tune into. A BBC investigation revealed that despite a 2019 directive to retire pagers, the practice persisted for years, leaving transplant patients and others in mental health crisis exposed without their knowledge. The breach is not merely a technical failure but a parable about institutional inertia: the tools we inherit outlast the wisdom that should govern them, and the silence they leave behind is unauditable.

In the quiet coordination of life-and-death medical decisions, NHS Blood and Transplant was doing something it should never have done: broadcasting transplant patients' names, dates of birth, organ details, and immunosuppression risk factors across an unencrypted pager network — visible to anyone tuned to the right frequency.

A BBC investigation uncovered the practice, which had continued despite a 2019 directive from then-Health Secretary Matt Hancock that NHS England should abandon pagers by 2021. NHSBT admitted the breach after being contacted by journalists, acknowledging that sensitive transplant data had been transmitted in plain text to hospital teams. No one could say whether it had been intercepted, or how many patients were affected — pagers are one-way receivers that leave no auditable trail.

The problem ran deeper than transplant coordination. Over ten days, the BBC found hundreds of messages crossing the same network from ambulance trusts, hospitals, and fire services. Mental health incidents were logged. Medication details were shared. The name of a patient in suicidal crisis was transmitted. The North West Ambulance Service has since withdrawn pagers entirely; the Northern Ireland Ambulance Service has largely done so.

Pagers were chosen for practical reasons — they penetrate thick hospital walls and carry long battery lives. But that same broadcast nature makes them catastrophically insecure. As one technology expert noted, messages can reach an entire building or even nationwide, and there is no way to know who is listening.

NHSBT's head of organ transplantation said the service had been surprised to learn the messages were unencrypted, accepted the breach, and has now stopped all sensitive pager transmissions. The Information Commissioner's Office confirmed it is making inquiries. The pager network operator noted its own terms of service warn against transmitting sensitive information over radio — a warning that went unheeded. The full scope of exposure remains, and likely will remain, unknown.

In the quiet coordination of life-and-death medical decisions, NHS Blood and Transplant was doing something it should never have done: broadcasting the names, dates of birth, and organ details of transplant patients across an unencrypted pager network, visible to anyone with the right frequency tuned in.

A BBC investigation uncovered the practice, which had continued despite a 2019 directive from then-Health Secretary Matt Hancock that the NHS in England should abandon pagers by 2021. The service admitted the breach after being contacted by journalists, acknowledging that sensitive information—tissue-match scores, immunosuppression risk factors, the identities of people waiting for organs—had been transmitted in plain text to hospital transplant teams using these antiquated devices. No one at NHSBT could say whether the data had been intercepted, or how many people had been affected, because pagers are one-way receivers that leave no auditable trail.

The problem ran deeper than transplant coordination. Over a ten-day period, the BBC found hundreds of messages crossing the same pager network from ambulance trusts, hospitals, and fire services. Mental health incidents were logged. Medication details were shared. The name of a patient in suicidal crisis was transmitted. The North West Ambulance Service and Northern Ireland Ambulance Service both used the system to send crew information including patient ages and medical details, though they said patient names were excluded from those messages. NWAS has since withdrawn pagers entirely; NIAS has largely done so.

Pagers were chosen for a reason. They work at low frequencies that penetrate buildings and elevators—particularly useful in hospitals with thick walls designed to shield against radiation. They have long battery lives and allow rapid information sharing when speed matters. But that same broadcast nature that makes them useful in hospitals makes them catastrophically insecure for sensitive data. Luca Arnaboldi, a technology expert at the University of Birmingham, put it plainly: pagers were never designed for privacy. Messages broadcast to a large area—potentially an entire building, or even nationwide—and anyone on the right frequency could receive them. There is no way to know who is listening, and no log of who accessed what.

Anthony Clarkson, NHSBT's head of organ transplantation, said the service had been surprised to learn the messages were not encrypted. "We accept it was a data breach," he stated, adding that NHSBT has now stopped sending any sensitive information to pagers and launched an internal investigation. The service reported the breach to the Information Commissioner's Office, which confirmed it is making inquiries. The Department for Health and Social Care said the NHS has been working to replace outdated technology, though it offered no timeline or explanation for why this particular vulnerability persisted years after the 2019 directive.

The pager network operator said it provides encrypted solutions and that customers determine how services are deployed. Its terms and conditions warn that radio signals may be intercepted and advise against transmitting sensitive information over radio or public networks—a warning NHSBT apparently did not heed. The Information Commissioner's Office noted that medical data is highly sensitive and that organisations have a legal responsibility to handle it securely. The full scope of exposure remains unknown, and likely will remain so. Pager broadcasts leave no trail. Whoever was listening—if anyone was—left no fingerprints.

We accept it was a data breach. We were surprised that these messages were not encrypted, and that vulnerability was there.
— Anthony Clarkson, NHSBT head of organ transplantation
Pagers broadcast messages to a large area—potentially a whole building or even nationwide—and anybody can receive it as long as they're on the right frequency. If any information on it were to be private, anybody could be listening to it.
— Luca Arnaboldi, technology expert and assistant professor at the University of Birmingham
Vuoi la storia completa? Leggi l'originale su BBC News ↗
Contattaci Domande frequenti