NHS Data Breach Exposes Risks of Unencrypted Pager Networks

NHS admits transplant patient data sent over unencrypted pagers

The recent NHS data breach involving unencrypted pager networks has brought renewed attention to the critical risks of legacy communication systems within healthcare. Sensitive transplant patient data was transmitted over an insecure channel, raising concerns about patient privacy and data protection in the UK’s National Health Service.

Details of the NHS Data Breach Involving Pager Networks

In June 2024, it was publicly disclosed that an NHS service responsible for coordinating transplant procedures across the UK had been transmitting confidential patient information using an unencrypted pager network. This revelation followed an internal review and subsequent admission by the NHS service that data was exposed to potential interception by unauthorised parties.

Specifically, the data transmitted included personal details of transplant patients, such as names, medical conditions, organ compatibility information, and logistical details of transplant operations. The exposure occurred because the pager network in use relied on legacy radio frequency technology without any form of encryption, making all transmitted messages accessible to anyone with the necessary radio equipment.

  • When: The breach was disclosed in June 2024, but the use of unencrypted pagers had been ongoing for years.
  • Who is affected: UK transplant patients whose information was communicated via the pager system, as well as medical staff involved in organ transplant coordination.
  • Products and versions: Legacy pager devices and radio networks, many of which pre-date modern encryption standards.
  • Sensitive data at risk: Patient names, organ match details, operation times, and other confidential medical information.

How the Pager Network Vulnerability Enabled Data Exposure

Pagers, long a mainstay in hospital communications, operate using radio frequencies to transmit text messages between staff. Historically, these systems were valued for their reliability and ability to function in areas with poor mobile coverage. However, most traditional pager networks transmit messages in cleartext, lacking any form of encryption or authentication.

In this NHS case, the service continued to use a public radio-based pager network to coordinate urgent transplant logistics. Anyone with a suitable receiver could potentially intercept and read these transmissions. Cybersecurity experts have long warned that radio-based pagers, particularly those on legacy networks, present a risk because:

  • Messages are broadcast unencrypted and can be intercepted by commercially available equipment.
  • No authentication ensures only intended recipients receive the messages.
  • Sensitive data, such as patient identifiers and medical details, are often included in cleartext transmissions.

The NHS data breach occurred because these inherent weaknesses were not addressed, allowing for the theoretical possibility that anyone monitoring the correct frequency could capture highly sensitive patient information. While there is no public evidence that malicious actors exploited this vulnerability, the NHS admitted that the exposure was real and ongoing until the issue was identified.

Timeline of the NHS Pager Data Breach

  • Pre-2024: NHS transplant services routinely used unencrypted pagers for critical communications.
  • Early 2024: Internal concerns were reportedly raised about the security of patient data transmitted via pager.
  • May 2024: An internal review confirmed that sensitive information was indeed being sent over insecure channels.
  • June 2024: Public disclosure of the breach, with the NHS service admitting to the use of unencrypted pagers and subsequent exposure of patient data.
  • Current exploitation status: The NHS service has stated there is no known evidence of malicious exploitation, but the risk of interception existed throughout the period of unencrypted use.

The breach has prompted an immediate review of communications protocols and accelerated plans to replace pagers with encrypted, modern communication tools.

Why This NHS Data Breach Matters

This event highlights the urgent need for the healthcare sector to phase out legacy technologies that cannot guarantee the confidentiality and integrity of sensitive data. Patient trust and privacy are fundamental, and the continued use of outdated systems puts both at risk. The breach underscores both the technical and regulatory challenges of securing medical information in complex, high-pressure environments like transplant coordination.

Key Actions for Organisations in Light of the Breach

  • Audit all legacy communication systems, especially pagers and radio networks, for security weaknesses.
  • Accelerate the migration to encrypted, authenticated messaging platforms for any sensitive communications.
  • Train staff on the risks of using outdated technologies for transmitting confidential information.
  • Review and update incident response plans to ensure rapid detection and mitigation of future breaches.

For healthcare organisations and any sector still reliant on legacy communications, this breach serves as a compelling warning to prioritise modernisation and data security as a matter of patient safety and regulatory compliance.

Originally reported by bbc.co.uk.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call