TechNewsReel
Live

NHS Blood and Transplant admits data breach via unencrypted pager network

A BBC investigation reveals sensitive organ transplant data and mental health records were broadcast over insecure radio frequencies.

TechNewsReel Newsroom · August 14, 2026

NHS Blood and Transplant (NHSBT) has admitted to a significant data breach after an investigation revealed the agency transmitted sensitive patient medical data over an unencrypted pager network. The failure exposed highly personal information to anyone with the right radio equipment, highlighting a dangerous reliance on legacy communication tools within the healthcare system.

According to a BBC investigation, the transmitted data included patient names, dates of birth, and specific organ transplant details, such as the types of organs offered or needed. The breach also exposed tissue-match scores and immunosuppression risk factors (cRF). Beyond NHSBT, the BBC intercepted hundreds of messages over a 10-day period from other emergency services, including ambulance trusts, hospitals, and fire services. These messages contained sensitive information regarding medication details and mental health incidents.

The persistence of legacy tech

Pagers remain prevalent in hospital environments because they operate at low frequencies that penetrate thick walls and elevators more effectively than mobile phones, while offering superior battery life. However, these systems are typically one-way broadcasts that send signals over wide areas. Luca Arnaboldi, a tech expert and assistant professor at the University of Birmingham, noted that these messages can be broadcast to an entire building or even nationwide, and anyone on the correct frequency can receive them.

While the pager network operator stated that it provides encrypted solutions, it clarified that customers determine how those tools are deployed. The operator further noted that clients are explicitly advised not to transmit sensitive data over radio networks.

Systemic security failures

This breach underscores a critical failure in protecting patient privacy and reveals a systemic dependence on outdated technology that fails to meet modern security standards. Because pager transmissions are one-way, recipients cannot be tracked, meaning NHSBT cannot determine if the data was intercepted by malicious actors or quantify exactly how many patients were affected. This creates what is described as an unauditable log of leaked information.

A missed deadline

The continued use of these devices persists despite previous government attempts to modernize. In 2019, former Health Secretary Matt Hancock announced a goal for the NHS in England to cease the use of pagers by 2021. Despite this directive, several services continued to rely on the technology, leading to the current vulnerability.

Anthony Clarkson, Head of organ transplantation at NHS Blood and Transplant, acknowledged the failure, stating, "We accept it was a data breach. We were surprised that these messages were not encrypted, and that vulnerability was there."

Sources

Get a notification when a big story breaks. A few a day at most — no spam.