NHS Transplant Service Sent Patients' Private Medical Data Over an Open Radio Network for Years
NHS Blood and Transplant used a pager system that broadcast donor names, birth dates and organ-matching scores without any encryption, meaning anyone with basic radio equipment could have been listening.

Key points
- NHS Blood and Transplant (NHSBT), the body that coordinates organ transplants across the UK, admitted it sent sensitive patient data over an unencrypted pager network for an unspecified number of years.
- Intercepted information included donor names, recipient dates of birth, organ types, tissue-match scores and immunosuppression risk ratings.
- The UK government told the NHS to stop using pagers by 2021; parts of the health service never did.
- NHSBT has now stopped sending patient data via pagers and reported the breach to the Information Commissioner's Office, the UK's data-protection regulator.
- A BBC investigation also found hundreds of unencrypted messages from ambulance trusts and hospitals covering mental health incidents, medication details and a patient's suicide attempt.
The NHS body responsible for matching organ donors with recipients has been broadcasting transplant patients' private medical records over a radio network that carried no encryption, meaning the signals were readable by anyone tuned to the right frequency. NHS Blood and Transplant confirmed the breach to the BBC, which first uncovered it, and has since reported the incident to the Information Commissioner's Office.
Encryption is the process of scrambling data so that only the intended recipient, holding the right digital key, can read it. Without it, a radio message is like a postcard: open to anyone who picks it up.
What exactly was sent in the open?
Transplant coordinators received pager messages containing donor names, recipient names, dates of birth, organ types, tissue-match scores and immunosuppression risk factors. These last two are clinical ratings that help doctors decide whether a patient's immune system will reject a donated organ.
Pagers are small, battery-powered radio receivers, popular through the 1980s and 1990s, that show short text messages on a tiny screen. Unlike mobile phones, they only receive signals; they cannot send them back. That one-way design is useful in hospitals, where thick, X-ray-shielding walls block phone signals but low-frequency pager signals pass straight through.
That same open broadcast is also the problem. Luca Arnaboldi, an assistant professor at the University of Birmingham, explained it bluntly: "It broadcasts messages to a large area, potentially a whole building, or even nationwide, and anybody can receive it as long as they're on the right frequency."
Anthony Clarkson, NHSBT's head of organ transplantation, said the service was "deeply sorry" and acknowledged it had been unaware the messages were unencrypted. "We were surprised that these messages were not encrypted, and that vulnerability was there," he said.
Should patients be worried?
NHSBT says it cannot confirm whether anyone intercepted the messages, because pager systems keep no log of who receives a broadcast. That unauditability is itself a serious problem.
The BBC's wider investigation found hundreds of additional unencrypted messages sent over ten days by ambulance trusts and fire services, including details of mental health crises and at least one patient's suicide attempt.
| Organisation | Data sent openly | Current status |
|---|---|---|
| NHS Blood and Transplant | Donor names, recipient names, DOB, organ type, tissue-match scores | Pager use stopped |
| North West Ambulance Service | Addresses, patient ages, medical details | Pagers fully withdrawn |
| Northern Ireland Ambulance Service | Crew dispatch details including patient ages | Pagers largely withdrawn |
If you are a transplant patient and want to know whether your data was among those sent, NHSBT is the right body to contact. It is also worth monitoring any correspondence from your transplant centre over the coming weeks.
The pager network operator said it does offer encrypted paging services, but that customers choose how to deploy them. It added that its terms and conditions warn against sending sensitive information over radio networks.
The government announced in 2019 that NHS England should phase out pagers by 2021. Parts of the health service never did. That gap between policy and practice is, at this point, the more embarrassing fact.



