The Information Commissioner's Office (ICO) has opened an enquiry after NHS Blood and Transplant (NHSBT) admitted to sending the sensitive medical data of transplant patients from across the UK over an unencrypted pager network.
The organisation, which co-ordinates transplants across the country, said it had been sending urgent messages to inform hospitals about opportunities for transplants via pagers.
However, following an investigation by the BBC, it learnt that when the system sent a message to a pager, the data was not encrypted.
According to the BBC, the messages in question detailed the types of organs available, and the names, dates of birth, tissue-match scores, and immunosuppression risk factors of the people receiving the transplants.
Pagers are small battery-operated radio receivers that can receive short text messages, numbers to call, or alerts.
In 2019, then-Health Secretary Matt Hancock announced that the NHS in England should stop using “outdated” pagers by 2021.
NHSBT said that following the BBC investigation, it took “immediate action” to stop sending patient identifiable information, and reported the incident to the Information Commissioner (ICO).
An ICO spokesperson said: “It is essential that people can trust organisations to handle their personal information securely and responsibly.
“People’s medical data is highly sensitive information, not only do people expect it to be handled carefully and securely, organisations also have a responsibility under the law.
“NHS Blood and Transplant reported an incident to us and we are making enquiries.”
An NHSBT spokesperson said: “Organ transplantation is a time-critical service where rapid communication is essential to save lives.
“To inform hospitals about an opportunity of a transplant for a patient on the waiting list, we send an urgent message. This is sent via a system to a hospital transplant team who receive these messages via email, SMS text and, until recently, pagers.
“We have learnt, when the system sent a message to a pager, the data was not encrypted.
“We took immediate action to stop sending patient identifiable information. We reported it to the Information Commissioner and our regulators, and are carrying out an internal investigation.
“We are deeply sorry for the concern this will cause patients and their families. Protecting their information is extremely important to us and we are committed to ensuring operational needs are balanced with the highest standards of information governance and data protection.”

