The Information Commissioner’s Office (ICO) is investigating NHS Blood and Transplant (NHSBT) following reports that sensitive patient information was routinely transmitted using an unencrypted pager network. The incident has raised important questions about the security of legacy systems and serves as a reminder that organisations must regularly assess whether longstanding technologies remain suitable for handling personal and special category data.
NHSBT was routinely transmitting sensitive patient information via an unencrypted pager network. The information reportedly included special category data:
- Patient names and dates of birth
- Organ requirements and availability details
- Tissue-matching scores
- Immunosuppression risk factors and other sensitive health information
It is currently unclear how many individuals may have been affected, or who may have received the messages, as recipients could not be tracked through the network. NHSBT is co-operating with the ICO as an investigation is underway.
This incident serves as an important reminder that data security obligations extend beyond cyber attacks and external threats. Legacy technologies and established processes can introduce significant risks if they are not regularly reviewed against current security and data protection requirements.
As Ann Bevitt, Partner at Cooley, noted:
“This incident clearly highlights the need for organisations to consider and assess security risks on an ongoing basis. It is not sufficient to treat compliance as a once-off obligation. Continuous review of the security aspects of technological systems is required on a continuing basis to ensure that personal data are adequately protected.”
Recommended Actions
- Review whether any legacy or unsupported communication technologies are being used to process personal data.
- Assess whether technical and organisational measures remain appropriate for the sensitivity of the information being handled.
- Maintain a programme of continuous security review, rather than treating compliance as a one-off exercise.
- Contact your TIAA DPO for guidance and support.