Independent Reviews
Plain black pocket pager and folded blue scrubs on a dark hospital desk
Data Protection Published 16 Aug 2026 6 min read1 source

NHS Transplant Data Was Sent Over an Unencrypted Pager Network

NHS Blood and Transplant has stopped sending patient information to pagers after a BBC investigation found names, dates of birth and transplant details travelling over interceptable radio signals.

By VPN Rocks Editorial Team

The short version

What you need to know

  • NHS Blood and Transplant acknowledged a breach after names, dates of birth, organ details and other transplant information were sent to hospital teams through an unencrypted pager network.
  • The service has stopped sending sensitive messages to pagers, reported the incident to the ICO and opened an internal investigation, but says it cannot tell whether the broadcasts were intercepted or how many people were affected.
  • A personal VPN cannot encrypt a separate one-way radio broadcast. Patients should rely on official notification and verification rather than assuming the incident exposed account passwords or every medical record.

What data was sent over the pager network?

A BBC investigation found that NHS Blood and Transplant sent transplant information to members of hospital teams using an unencrypted pager network. The messages included patient names, dates of birth, organs being offered or needed, tissue-match scores and immunosuppression risk factors.

NHSBT does not operate pagers itself, but its urgent communication system could deliver the same message by email, SMS and pager. The service says it was surprised to learn the pager path was unencrypted. It acknowledged a data breach, stopped sending sensitive information through that path, reported the incident to the ICO and began an internal investigation.

Why the scale and access remain uncertain

Pager networks broadcast one-way radio messages rather than creating a private, recipient-authenticated session. The network operator told the BBC that radio signals may be intercepted and that customers decide how its services are used. A security researcher explained that anyone receiving the right frequency could potentially collect a broadcast.

NHSBT says pager recipients cannot be tracked, so it does not know whether an unauthorised person actually accessed the data or how many people may have been affected. That distinction matters: the confirmed problem is insecure transmission of sensitive information, not confirmed publication of every message or evidence that a criminal collected it.

The issue extends beyond one transplant service

The BBC says it observed hundreds of messages over ten days from ambulance trusts, hospitals and fire services. Examples included addresses, ages, mental-health incidents, medication information and details of a person attempting suicide. Some services said their messages excluded names, which reduces direct identification but does not necessarily remove sensitivity.

Pagers can work deep inside hospitals, use little power and deliver urgent alerts reliably, which helps explain why they persisted after the NHS in England was told to phase them out by 2021. Reliability does not make a broadcast confidential, however. Legacy technology needs either a secure service designed for sensitive content or strict limits on what is sent.

What patients should do now

Do not assume that every transplant patient's full medical file, login details or NHS account password was exposed. The reported pager fields were specific to operational messages, and the number of affected people remains unknown. Watch for a direct notice from NHSBT or another provider and follow the incident-specific support it gives.

Treat unexpected calls, messages or email mentioning a transplant, medication or appointment as unverified even if the details sound accurate. Contact the service through an official NHS page, letter or known number rather than using a link or number supplied by the caller. Keep healthcare and email passwords unique and enable multi-factor authentication where offered, but do not change credentials solely because a separate pager broadcast occurred unless an official notice says account data was involved.

Where a VPN helps — and where it does not

A reputable VPN can protect internet traffic leaving a patient's phone or laptop on public Wi-Fi. It cannot reach back into an NHS communication workflow or encrypt a one-way radio broadcast sent over a separate pager network.

An enterprise VPN would not automatically solve this either: the sensitive data must remain inside an approved encrypted channel from sender to authenticated recipient. The relevant controls are secure messaging, data minimisation, service configuration, auditability and removal of sensitive content from legacy broadcasts.

VPN Rocks view

This is a useful reminder that encryption claims need an end-to-end data-path check. An email or portal may be secure while a parallel delivery option silently broadcasts the same content without comparable protection.

The practical lesson for organisations is to inventory every output, including old systems kept for resilience. For patients, the lesson is narrower: verify any follow-up and wait for confirmed scope rather than treating uncertainty as proof that all records have been stolen.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps