NHS service admits data breach due to pager use

0
4

NHS service admits data breach due to pager use

A doctor dressed in blue scrubs puts a pager on his trousers.Image source, Getty Images
ByDan JohnsonWest of England correspondentEmma HallettWest of England producer and Chris KellyWest of England digital editor
  • Published

The sensitive medical data of transplant patients from across the UK was routinely sent over an unencrypted pager network, an NHS service has admitted.

A BBC investigation found NHS Blood and Transplant (NHSBT) sent the names, dates of birth and types of organs being offered or needed to members of hospital transplant teams who were using pagers, unaware they were not encrypted.

In 2019, then-Health Secretary Matt Hancock announced the NHS in England should stop using pagers by 2021, but some parts of the organisation have continued doing so.

NHSBT said it was “deeply sorry” and has reported the data breach to the Information Commissioner. It added it has now stopped sending patient data in this way.

Pagers are small battery operated radio receivers – popular in the 1980s and 1990s – that can receive short text messages, numbers to call, or alerts.

They are a one-way communication system and only able to receive messages, not send them, which was why they largely fell out of public use as more and more people started carrying mobile phones.

While NHSBT itself does not have any pagers, it was using a system that sent messages to them.

Recipients of pager messages cannot be tracked, therefore NHSBT said it was unclear whether the unencrypted information was accessed or how many people may have been affected.

Pagers were originally used because they allowed for rapid information sharing. They also work at a low frequency and are able to penetrate buildings and elevators and particularly hospitals – which can have thickened walls to protect people from X-rays and other radiation. They also have long battery lives.

To play this video you need to enable JavaScript in your browser.

This video can not be played

The NHS is legally required to protect patients’ data. The Department for Health added that where “legacy technologies” were still being used, any patient information should be “handled securely and in line with data protection requirements”.

As part of our investigation, the BBC found messages that went beyond just NHSBT.

Hundreds of messages were sent across 10 days on the pager network by ambulance trusts, hospitals and fire services.

A variety of different details were transmitted, including mental health incidents, medication details, and the name of a patient trying to take their own life.

Head of organ transplantation at NHS Blood and Transplant, Anthony Clarkson. He is stood upstairs overlooking a building atrium. He is wearing a blue suit, pink shirt and blue tie. He is looking directly at the camera.Image source, NHSBT

NHS Blood and Transplant, which co-ordinates transplants across the country, sent messages that detailed the types of organs available, and the names, dates of birth, tissue-match scores, and immunosuppression risk factors (cRF) of the people receiving the transplants.

NHSBT acknowledged this was a data breach, after being alerted by the BBC.

The service’s head of organ transplantation, Anthony Clarkson, said it had been using a system for urgent communications to transplant teams where speed can be critical. Messages were sent by email, SMS text and, until recently, to pagers.

“We accept it was a data breach,” Clarkson said.

“We were surprised that these messages were not encrypted, and that vulnerability was there.”

He added that NHSBT has now taken urgent measures to stop sending any messages containing sensitive information to the pager network and it has launched an internal investigation “to make sure nothing like this happens again”.

To play this video you need to enable JavaScript in your browser.

This video can not be played

Luca Arnaboldi, a tech expert and assistant professor at the University of Birmingham, said he was very concerned by the risks pager use could present to the NHS, adding they were “never meant for privacy”.

“It broadcast messages to a large area – potentially a whole building – but even nationwide, and anybody can receive it as long as they’re on the right frequency,” added Arnaboldi.

“If any information on it were to be private, anybody could be listening to it. It could cause some serious security issues.

“At the worst case, there is an unauditable log of leaked information.

“What’s even worse is we have no idea what somebody could do with this.”

The company which owns and operates the pager network said it provides encrypted paging and secure messaging solutions, with “customers determining how those services are deployed”.

It added that it has “no visibility of, or control over, the content transmitted by its customers”.

It also said its terms and conditions make clear that radio signals may be intercepted, and it advises customers not to transmit sensitive or personal information over radio or public networks.

Other pager users were the North West Ambulance Service (NWAS) and Northern Ireland Ambulance Service (NIAS), which sent messages with details for crews such as addresses, patient ages, and medical information.

Both services said the messages did not include patients’ names, while NWAS said pagers had now been fully withdrawn and for NIAS largely withdrawn.

Health and social care in Northern Ireland is a devolved matter, and therefore the responsibility of the Department of Health NI, rather than the UK Department of Health.

The BBC has approached Department of Health NI for comment.

A spokesperson for NIAS said it “will always recognise best practice across the UK”.

An Information Commissioner Office spokesperson said: “People’s medical data is highly sensitive information, not only do people expect it to be handled carefully and securely, organisations also have a responsibility under the law.

“NHS Blood and Transplant reported an incident to us and we are making inquiries.”

The Department for Health and Social Care said the NHS has “made progress in replacing outdated technology and is working to ensure staff have access to secure, reliable digital tools that support safe, high-quality patient care”.

Get in touch

Tell us which stories we should cover in Bristol

Follow BBC Bristol on Facebook, external, X, external and Instagram, external. Send your story ideas to us on email or via WhatsApp on 0800 313 4630.

More on this story

Related internet links

A thin, grey banner promoting the News Daily newsletter. On the right, there is a graphic of an orange sphere with two concentric crescent shapes around it in a red-orange gradient, like a sound wave. The banner reads: “The latest news in your inbox first thing.”

Get our flagship newsletter with all the headlines you need to start the day. Sign up here.

Disclaimer : This story is auto aggregated by a computer programme and has not been created or edited by DOWNTHENEWS. Publisher: BBC