
NHS Blood and Transplant Exposed UK Patient Data Via Unencrypted Pagers
NHS Blood and Transplant (NHSBT) has acknowledged a substantial data breach that compromised the medical records of numerous transplant patients throughout the UK. The incident, which unfolded in February, saw sensitive patient information transmitted over an unencrypted pager system.
The exposed data included patients' names, dates of birth, and specific details pertaining to their transplant procedures. While NHSBT maintains that there is no evidence of malicious access or misuse of the data, the unencrypted nature of the pager network meant that anyone with appropriate receiving equipment could intercept these transmissions.
This revelation brings into sharp focus the continued reliance on outdated communication technologies within critical public services. Despite advancements in secure digital communications, the use of pagers, some of which operate on technology dating back decades, persists. Critics argue that such vulnerabilities highlight a broader underinvestment in robust, secure IT infrastructure across the National Health Service.
NHSBT has stated that it is implementing measures to enhance data security and is in the process of phasing out the use of pagers for sensitive communications. However, for a service handling some of the most critical medical procedures, the exposure of such deeply personal data through an easily intercepted medium raises serious questions about the organisation's diligence in protecting patient privacy.






