Why an NHS Pager Data Breach Can Start With £20 of Kit

NHS Blood and Transplant is looking into how patient information moved over a pager network that has never been encrypted — and the kit needed to listen in costs less than a takeaway.

Why an NHS Pager Data Breach Can Start With £20 of Kit

NHS Blood and Transplant is investigating an NHS pager data breach, the BBC reports. The organisation is not a hospital trust. It is the special health authority that collects blood donations across England and runs the matching process deciding which patient on the transplant list gets an organ tonight. Its message traffic is, almost by definition, some of the most sensitive in the health service.

Here is the part that surprises people. Pager messages are not encrypted. The two protocols the NHS relies on, POCSAG and FLEX, encode text so a small device can display it, but they do not scramble it. Whatever goes out over the air can be picked up by anyone within range who owns the right cheap hardware, and the sender never learns it happened.

That hardware costs roughly £20. A software-defined radio dongle sells for about $20, and an antenna adds a couple of pounds. Nobody has to break into a system, guess a password or send a convincing phishing email. They just have to be nearby and listening — which is why this weakness has never really been fixed, only postponed.

Why the NHS Still Runs on 1980s Technology

The NHS operates around 130,000 pagers, roughly one in every ten still in use anywhere on earth, according to TechCrunch's reporting. Ministers instructed trusts to phase them out by the end of 2021. Plenty did not. Pagers survive because they do the one thing phones struggle with inside a hospital: they work in lead-lined radiology suites, concrete basements and steel-framed wards where mobile signal dies.

They also run for days on one battery, cost almost nothing, and cannot be locked out or crash at the worst possible moment. For a crash call or a 3am organ offer, reliability beats sophistication. The cost of that bargain is that the message goes out to everyone in range, not just the person wearing the pager.

How an NHS Pager Data Breach Can Happen

There is no dramatic single moment in a leak like this. An NHS pager data breach is usually the slow accumulation of perfectly ordinary messages, read by someone who was never meant to see them, over weeks or months.

Encoded Is Not Encrypted

Encoding turns letters into a signal a pager can display. Encryption turns them into gibberish without a key. Pager networks do the first and skip the second. Suppliers have offered better for years — paging firm PageOne told TechCrunch that encrypted services are available if required — but they cost more, so many organisations stayed on the basic tier.

The £20 Listening Post

A dongle the size of a USB stick, free decoding software and a length of wire is the whole kit. Point it near a hospital site and messages arrive as plain text on a laptop: names, addresses, ward numbers, the reason somebody dialled 999. No alarm sounds at the other end, because nothing has been touched.

Why Nobody Notices

Radio reception is passive. Unlike a hacked server, there are no logs, no failed logins, no odd traffic patterns to spot. An organisation tends to find out only when someone reports it, publishes it, or accidentally leaves the evidence in public view — which is precisely what happened the last time this made headlines.

Why an NHS Pager Data Breach Can Start With £20 of Kit

The Bedroom Rig That Broadcast 999 Calls

In October 2019, security researcher Daley Borda found an internet-connected webcam with no password on it. The camera pointed at a computer screen inside a house in north London, where an amateur radio enthusiast had built a rig decoding NHS pager traffic. Borda, watching from Florida, could read the name, address and injury of people who had just called 999.

People don't necessarily understand the difference between encryption and encoding.

That was Andy Keck, an electronics and radio hobbyist quoted at the time. Sarah Jamie Lewis, executive director of Open Privacy, called the messages trivially interceptable. Asked whether it knew its pager messages were unencrypted and interceptable, one trust gave a one-word answer: yes. Seven years later, the underlying technology has not changed.

How This Sits Against Past NHS Data Failures

NHS Blood and Transplant has faced the Information Commissioner before, over something unrelated. In 2023 the ICO reprimanded it after untested code reached the live organ-matching system, leaving five adult patients off the non-urgent liver matching run between 11 and 18 September 2019. The regulator had drafted a £749,856 fine before settling on a public reprimand instead.

Scale is worth holding in mind. The Synnovis ransomware attack of 3 June 2024 hit the pathology lab serving Guy's and St Thomas' and King's College Hospital; a forensic investigation later confirmed records on more than 90,000 NHS patients were stolen, and it is believed to have contributed to at least one patient's death. An NHS pager data breach is smaller, but it drips steadily rather than bursting once.

What to Watch For Next

Under UK GDPR, an organisation must notify the ICO of a personal data breach within 72 hours of becoming aware of it, and must tell affected individuals directly where the risk to them is high. Three things will show how serious this is:

  • Whether NHSBT states how many people were affected, and over what period
  • Whether individual notification letters go out, rather than a website statement
  • Whether the ICO opens a formal investigation instead of accepting an internal review

If you donate blood, sit on a transplant waiting list, or have a relative treated through NHSBT, you cannot patch a radio signal yourself. What you can do is submit a subject access request to see what the organisation holds about you, keep any letter it sends, and complain to the ICO if the response does not stack up. Watch for that regulator's next move — it will tell you far more than any press statement.