NHS Blood and Transplant investigate data breach due to pager use

NHS Blood and Transplant investigate data breach due to pager use

An NHS service has acknowledged that sensitive information related to transplant patients across the UK was being transmitted over an unencrypted pager system. A BBC investigation revealed that NHS Blood and Transplant (NHSBT) routinely sent details such as patients’ names, dates of birth, and the types of organs either offered or required, using pagers, without knowing that these communications were not secured by encryption.

Despite a 2019 announcement by then-Health Secretary Matt Hancock that the NHS in England should stop using pagers by 2021, some departments, including parts of NHSBT, continued to rely on this outdated technology. NHSBT expressed its regret over the situation, describing it as a data breach, and confirmed it has informed the Information Commissioner about the incident. The organisation has since ceased sending patient information via the pager network.

Pagers, popular from the 1980s and 1990s, are small radio receivers intended to receive brief messages or alerts. Because they operate solely as one-way receivers and cannot send messages, they gradually fell out of favor as mobile phones became widespread. Although NHSBT itself does not operate pagers, it used a system that delivered messages to them. The inability to track message recipients has left NHSBT uncertain about whether the unencrypted information was intercepted or how many individuals might have been impacted.

The technology was initially adopted in healthcare due to its ability to quickly transmit information and effectively penetrate building structures like hospital walls and elevators, where other wireless signals might struggle. However, this reliance on legacy systems comes with risks. A tech expert, Luca Arnaboldi, highlighted that pager messages, which can be received by anyone tuned to the correct frequency, were “never meant for privacy” and warned of serious security issues arising from the technology. NHSBT’s head of organ transplantation, Anthony Clarkson, acknowledged the data breach, noting surprise that the messages lacked encryption and outlining ongoing steps to prevent a recurrence, including an internal review

Read the full article from The BBC here: Read More