
An NHS service has reportedly admitted to a data breach after the medical information of transplant patients from across the UK was sent over an unencrypted pager network, according to a report by BBC News.
The breach reportedly involved sensitive medical data belonging to patients awaiting or recovering from organ transplants being transmitted via a paging system that lacked encryption, meaning the information could potentially have been intercepted by anyone with the right equipment.
What Happened
According to the BBC, the NHS service in question has acknowledged the issue, which reportedly affected patients across the UK involved in transplant care. Pagers have long been used within parts of the NHS for urgent clinical communication, but the use of an unencrypted network for transmitting patient data raises significant concerns about data protection and patient privacy.
Details of exactly how long the practice had been in place, and how many patients were affected, were not fully specified in the available reporting. The NHS service has reportedly confirmed the breach occurred, though further specifics about the scope of the incident were not disclosed in the excerpt of the original report.
Why It Matters
Data breaches involving medical information are treated with particular seriousness under UK data protection law, given the sensitivity of health records. Transplant patients’ data can include highly personal medical histories, treatment plans, and other confidential details that, if exposed, could compromise patient privacy and trust in NHS systems.
The reliance on older technology such as pagers, which many organisations phased out due to security concerns, has previously drawn scrutiny across healthcare systems. Unencrypted networks are generally considered vulnerable to interception, which is why more modern, secure communication methods have been favoured elsewhere in the health service.
The NHS is expected to face questions over how the breach occurred and what steps are being taken to prevent similar incidents from happening again. Further updates on the investigation and any response from regulators are likely to follow as more information becomes available.

