1 month ago
NHS admits transplant patient data sent via unencrypted pagers
Imagine doctors needed a quick way to tell each other important things about people waiting for organ transplants.
They used old pagers, little beepers from the 1980s that can receive short messages but cannot send replies.
But the messages included people's names, birthdays and health details, and they were not protected with a secret code.
That means other people might have been able to see them.
The NHS said it was very sorry and stopped sending private information this way.
It also told the Information Commissioner's Office, the UK office that protects people's data.
This was surprising because the NHS was asked years ago to stop using pagers.
The problem was not only about transplants — ambulances, hospitals and fire services also sent sensitive information through the same system.
Nobody knows for sure if anyone outside the hospitals ever saw the messages, and that is why people are worried.
NHS Blood and Transplant sent transplant patients' names, dates of birth and organ details over an unencrypted pager network, according to a BBC investigation.
NHSBT has stopped sending patient information via the system, reported the incident to the Information Commissioner's Office and launched an internal investigation.
The NHS in England was told in 2019 by then-health secretary Matt Hancock to stop using pagers by 2021, yet some parts of the service continued relying on the technology.
The issue went beyond transplants: hundreds of messages sent over a 10-day period by ambulance trusts, hospitals and fire services contained mental health details, medication information and patient ages.
NHSBT said it is 'deeply sorry' and cannot determine whether anyone outside the intended recipients accessed the messages because pager-network recipients cannot be tracked.
- Who
- NHS Blood and Transplant (NHSBT), along with ambulance trusts, hospitals and fire services
- What
- Sensitive patient information was sent over an unencrypted pager network, constituting a data breach
- Where
- England, with messages also involving Northern Ireland Ambulance Service
- When
- Revealed by a BBC investigation after the NHS had been told in 2019 to phase out pagers by 2021
- Why
- Transplant decisions are time-sensitive and teams need urgent information quickly, but the legacy pager network lacked encryption
Key facts
- Organisation involved
- NHS Blood and Transplant (NHSBT)
- Data exposed
- Names, dates of birth and organ-related information
- Regulator notified
- Information Commissioner's Office
- Other users of network
- Ambulance trusts, hospitals and fire services
- NHS response
- Stopped sending patient information via pagers, launched internal investigation
- 2019 instruction
- NHS in England told to stop using pagers by 2021
- Organisations named
- North West Ambulance Service and Northern Ireland Ambulance Service
Quotes
NHS Blood and Transplant
Chief organisation handling organ transplantation in the UK
“"We are deeply sorry."”
easterneye.biz









