Sensitive medical information belonging to transplant patients across the UK was routinely transmitted over an unencrypted pager network, according to a BBC investigation.
NHS Blood and Transplant (NHSBT), which co-ordinates organ transplants across the country, acknowledged to the BBC that the practice constituted a data breach after being alerted to it by the broadcaster.
The investigation found that names, dates of birth and information about organs being offered or required were sent to members of hospital transplant teams using pagers, with NHSBT unaware that the communications were not encrypted.
NHSBT told the BBC it was “deeply sorry” and said it had reported the data breach to the Information Commissioner. The service has also stopped sending patient information through the pager system.
The BBC reported that NHSBT itself does not use pagers, but had been using a communications system capable of sending messages to them.
Because recipients of pager messages cannot be tracked, NHSBT said it was unclear whether the unencrypted information had been accessed or how many people may have been affected.
The BBC investigation found that information transmitted by NHSBT included details of the types of organs available, as well as the names and dates of birth of transplant recipients, tissue-match scores and immunosuppression risk factors, known as cRF.
Anthony Clarkson, NHSBT’s head of organ transplantation, said the organisation had been using the system for urgent communications with transplant teams, where information may need to be shared rapidly.
Messages were distributed through email and SMS as well as, until recently, pagers.
Pagers are small battery-operated radio receivers capable of receiving short text messages, telephone numbers and alerts. Unlike mobile phones, they operate as a one-way communication system and cannot send messages.
The technology was widely used during the 1980s and 1990s before largely falling out of public use as mobile phones became commonplace.
However, pagers have continued to have practical uses within healthcare environments. Their low-frequency signals can penetrate buildings and lifts, including hospitals with thickened walls designed to protect against X-rays and other forms of radiation, while the devices also offer long battery life.
In 2019, then-Health Secretary Matt Hancock announced that the NHS in England should stop using pagers by 2021, although parts of the health service have continued to rely on the technology.
The Department of Health said that where “legacy technologies” were still being used, any patient information should be “handled securely and in line with data protection requirements”.
The NHS is legally required to protect patients’ data.
The BBC’s investigation also found that sensitive information transmitted across the pager network extended beyond NHSBT.
Hundreds of messages were sent over a 10-day period by ambulance trusts, hospitals and fire services, according to the broadcaster, containing information including mental health incidents, medication details and the name of a patient attempting to take their own life.
The North West Ambulance Service (NWAS) and Northern Ireland Ambulance Service (NIAS) were among the organisations found to have used pagers to send information to crews.
Recommended reading
- 70% of Shoppers Prefer Humans Over AI for High-Stakes Purchases
- Brits Turn to AI Chatbots for Financial Advice, But Can We Trust Them?
- AI Tax Advice Could Sink Businesses, Accountants Warn
- UK Consumers Trust AI Search, But Should They?
According to the BBC, those messages included addresses, patient ages and medical information. Both ambulance services said patients’ names were not included.
NWAS said pagers have now been fully withdrawn from use, while NIAS said they have largely been withdrawn.
Health and social care in Northern Ireland is a devolved matter and falls under the responsibility of the Department of Health NI rather than the UK Department of Health.





