Secretus logo

NHS Pager Data Breach: Sensitive Patient Handoffs Need Encryption

·8 min read

NHS Blood and Transplant has acknowledged that sensitive transplant-patient data was sent through an unencrypted pager network used by hospital teams across the UK. A BBC investigation found that the messages included names, dates of birth, the types of organs offered or needed, tissue-match scores and immunosuppression risk factors. NHSBT says it has stopped sending sensitive information to pagers, opened an internal investigation and reported the incident to the Information Commissioner's Office.

The disclosure is not evidence that every message was intercepted or misused. NHSBT says pager recipients cannot be tracked, so it does not yet know whether an unauthorized person received the information or how many people may be affected. The confirmed failure is that identifiable medical data was broadcast without encryption through a channel that was not designed to keep message content private.

What NHSBT confirms

NHSBT does not operate the pagers itself. Its urgent-communication system sent messages by email, SMS and, until recently, to pagers held by transplant teams. Anthony Clarkson, NHSBT's head of organ transplantation, told the BBC that the service accepted this was a data breach and was surprised to learn that the pager messages were not encrypted.

NHSBT says speed is critical when an organ becomes available. That operational need explains why a fast, resilient notification channel remained in use; it does not make personal and medical details safe to broadcast. After the BBC alerted the service, NHSBT stopped sending messages containing sensitive information to the pager network and began investigating how the workflow was approved and operated.

The ICO separately confirmed to the BBC that NHSBT reported an incident and that the regulator is making inquiries. At publication, neither NHSBT nor the ICO has published a victim count, a duration for the practice or evidence that a third party captured the transplant messages.

Why an unencrypted pager message is not private

A pager is a one-way radio receiver. Its practical strengths include wide coverage, long battery life and reliable reception inside thick-walled buildings where other services may struggle. But an unencrypted broadcast can be received by equipment tuned to the same frequency; the sender does not obtain a trustworthy record of every receiver that heard it.

The pager-network operator told the BBC that it offers encrypted paging and secure messaging options, while customers decide how those services are deployed. It also said its terms warn customers not to transmit sensitive or personal information over radio or public networks. The lesson is therefore more precise than “pagers are insecure”: a broadcast channel without content encryption must not carry identifiable clinical data.

Separate the urgent alert from the sensitive record

Time-critical work does not require every detail to travel in the first notification. A safer design treats the pager, SMS or push message as a wake-up signal and moves the sensitive context to a controlled system.

  1. Minimize the alert. Send a non-identifying case reference, priority and callback instruction—not a name, date of birth, diagnosis or organ requirement.
  2. Require authenticated retrieval. The clinician should open an approved clinical system from a managed device to view the patient context.
  3. Authorize by role and current duty. Access should reflect who is on call and which transplant case they are handling, then expire when the task ends.
  4. Keep an auditable trail. Record who opened the protected information and when, rather than relying on an untraceable broadcast.
  5. Design a safe fallback. If the primary system is unavailable, use a documented emergency channel with minimum necessary data, recipient verification and a retrospective review.

What healthcare teams should review now

  • Inventory pager, SMS, email, radio and notification gateways that can receive patient information.
  • Inspect message templates and integrations, not just the devices, for names, dates of birth, case notes and other identifiers.
  • Verify whether encryption is enabled end to end and who controls the keys and recipient list.
  • Test whether former staff, lost devices or shared receivers can still receive operational messages.
  • Define an incident path for stopping a data flow without disrupting urgent care.
  • Include legacy communications in data-protection impact assessments and supplier reviews.

Where Secretus fits—and where it does not

Secretus can help an authorized team transfer a temporary password, recovery code or scoped token without leaving the plaintext in a long-lived email or chat thread. A short-lived, one-time handoff can be useful when responders need to restore an approved clinical service or provide emergency access to a trusted administrator.

Secretus is not an electronic health record, an NHS-approved clinical messaging system or a substitute for the organization's privacy, safety and procurement controls. Patient records should not be moved into an ad-hoc secret-sharing workflow. The product-specific lesson is to keep operational credentials out of broadcasts and persistent conversations, while sensitive clinical information remains inside the governed system built to handle it.

What remains unknown

NHSBT has not disclosed how long the messages were sent, the number of patients or teams involved, whether any unauthorized receiver captured them, or whether the information was exploited. The BBC also found sensitive pager traffic from other public services, but those messages should not be folded into the NHSBT incident count. Each organization has its own systems, facts and notification duties.

Sources

Share a secret the safe way

Start a 14-day trial to send; recipients open one-time links without an account.

Try Secretus