Published: 14 August 2026 | The English Chronicle Desk | The English Chronicle Online
Sensitive medical information belonging to transplant patients across the UK was routinely transmitted through an unencrypted pager network, prompting NHS Blood and Transplant to admit a data breach and launch an internal investigation.
The disclosure has raised fresh concerns about the continued use of ageing communication technology within parts of the health service, particularly where highly confidential information is involved.
NHS Blood and Transplant, the organisation responsible for coordinating organ donation and transplantation services across England and the wider UK, confirmed that it had been sending patient information to hospital transplant teams through a system capable of delivering messages to pagers.
The information included patients’ names, dates of birth, the types of organs being offered or required, tissue-match scores and immunosuppression risk factors. The messages were intended to help transplant teams respond rapidly when organs became available, when timing can be critical.
However, the system was not encrypted, meaning the radio transmissions could potentially be intercepted by others who had access to the relevant frequency.
NHSBT said it was “deeply sorry” and confirmed that it had reported the incident to the Information Commissioner’s Office. It has now stopped sending sensitive patient information through the pager network.
The organisation said it had been surprised to discover that the messages were not encrypted and acknowledged that the vulnerability had existed within the communication system.
Anthony Clarkson, NHSBT’s head of organ transplantation, said the service had been using the system for urgent communications with transplant teams. Information could previously be transmitted by email, SMS and, until recently, pagers.
“We accept it was a data breach,” Clarkson said.
He added that urgent measures had been taken to prevent any messages containing sensitive information from being sent through the pager network and that an internal investigation had been launched to establish what happened and prevent a recurrence.
One of the most difficult questions is determining whether anyone actually accessed the information.
Because pager recipients cannot be tracked in the same way as users of modern digital communication platforms, NHSBT said it was unclear whether the unencrypted messages had been intercepted or how many people could potentially have been affected.
That uncertainty is particularly concerning because medical information is among the most sensitive forms of personal data.
The Information Commissioner’s Office said people expect their medical information to be handled securely and that organisations have legal responsibilities to protect it.
“NHS Blood and Transplant reported an incident to us and we are making inquiries,” an ICO spokesperson said.
The incident also highlights the continuing presence of pagers within parts of the NHS despite years of government efforts to replace them.
Pagers became widely associated with hospitals and emergency services because they were reliable, relatively inexpensive and capable of delivering alerts rapidly. They also have long battery lives and can operate effectively in environments where mobile phone signals may be unreliable.
Their radio signals can penetrate hospital buildings, including areas with thick walls designed to provide protection from X-rays and other radiation.
Those characteristics made pagers particularly useful for healthcare workers who needed to receive urgent messages.
But the technology also has major limitations when it comes to privacy.
Unlike modern encrypted messaging systems, traditional pager broadcasts can potentially be received by anyone able to access the relevant transmission. Messages are also generally one-way, meaning the recipient cannot reply directly through the pager.
Technology experts say this makes them fundamentally unsuitable for transmitting confidential medical information unless additional security measures are used.
Luca Arnaboldi, an assistant professor at the University of Birmingham, said he was particularly concerned about the risks posed by pager use within the NHS.
Pagers, he said, were “never meant for privacy”.
He explained that broadcasts could potentially cover large areas and that anyone able to receive the appropriate frequency could potentially listen to the transmission.
The absence of a reliable audit trail creates another problem. If a message is intercepted, organisations may not be able to establish who accessed it or exactly what information was obtained.
That is particularly problematic when medical information is involved because leaked data could potentially be used for identity fraud, harassment or other forms of exploitation.
The BBC investigation that prompted NHSBT’s admission also found that pager use extended well beyond transplant services.
Hundreds of messages were transmitted over a 10-day period across the network by ambulance trusts, hospitals and fire services.
The information reportedly included details relating to mental health incidents, medication and patients in medical emergencies.
One message included the name of a patient who was attempting to take their own life.
Ambulance services also used the system to provide operational information to crews, including addresses, patient ages and medical details.
The North West Ambulance Service said its pagers had now been fully withdrawn. The Northern Ireland Ambulance Service said pagers had largely been withdrawn from use.
Both services stressed that patient names were not included in the messages they transmitted.
The continued use of such systems has nevertheless raised questions about whether organisations have moved quickly enough to replace technologies that were designed for a very different era of communications.
In 2019, then-Health Secretary Matt Hancock announced that the NHS in England should stop using pagers by 2021. The policy was intended to encourage the health service to adopt more modern communication systems.
However, the NHS is a vast organisation made up of numerous trusts and services, and replacing legacy technology across every part of the system has proved complicated.
Pagers have remained attractive in some healthcare environments because of their reliability, long battery life and ability to operate inside large hospital buildings.
The problem is not necessarily the existence of pagers themselves but the nature of the information being transmitted through them.
The company that operates the pager network said it provides encrypted paging and secure messaging solutions, while customers determine how those services are deployed.
It said it had no visibility of or control over the content transmitted by customers.
The company also pointed to its terms and conditions, which warn that radio signals may be intercepted and advise customers not to transmit sensitive or personal information over radio or public networks.
That response places much of the responsibility on organisations deciding what information to send through the network.
For NHSBT, the breach demonstrates the risks of relying on legacy systems when speed and confidentiality must operate together.
Organ transplantation is an especially demanding area of healthcare because opportunities can arise suddenly. Teams may have only a limited period to determine whether an organ is suitable and coordinate the necessary procedures.
That operational pressure may help explain why the pager system remained in use.
But urgency cannot remove the requirement to protect patients’ personal information.
The Department of Health and Social Care said the NHS had made progress in replacing outdated technology and was working to ensure staff had access to secure and reliable digital tools.
The department also stressed that where legacy technologies remain in use, patient information must be handled securely and in accordance with data protection requirements.
The issue is particularly significant because the breach may not be limited to one isolated communication channel.
The wider investigation found that multiple emergency and healthcare organisations were still using pagers for operational messages. Although many of those messages did not contain names, information such as patient ages, locations, medication details and medical circumstances can still constitute sensitive personal information.
Northern Ireland presents an additional complication because health and social care are devolved matters. Responsibility therefore rests with the Northern Ireland Department of Health rather than the UK Department of Health and Social Care.
The Northern Ireland Ambulance Service said it recognised the importance of following best practice across the UK.
Meanwhile, the ICO’s inquiries will determine what further action may be necessary in relation to the NHSBT incident.
For patients whose information was transmitted through the system, one of the biggest concerns may be the uncertainty surrounding whether their information was actually intercepted.
NHSBT’s inability to identify recipients or establish whether the broadcasts were accessed means that some questions may never be fully answered.
The incident is therefore more than a story about old technology.
It raises fundamental questions about how the NHS manages sensitive information while balancing the demands of rapid communication, operational reliability and cybersecurity.
Healthcare organisations increasingly rely on digital systems, but many still operate alongside infrastructure that dates back decades. Those systems may remain useful for specific operational purposes, yet their limitations become increasingly serious when personal information is involved.
The NHSBT breach is a warning that modern healthcare security cannot depend solely on whether a communication system remains operational. It must also consider whether information transmitted through that system is protected from interception and whether there is a clear record of who can access it.
For NHSBT, the immediate response has been to stop sending sensitive patient information over the pager network and investigate how the vulnerability remained undiscovered.
The longer-term challenge will be ensuring that other NHS organisations learn from the incident before a similar breach occurs elsewhere.
The health service may have moved a long way from the pager era, but the latest incident shows that some of its communications infrastructure has not moved at the same speed as the technology surrounding it.























































































