PrivacySignal
Breach

NHS admits data breach by sending patient data via pagers

DataBreaches.net · · International · Data Breaches

The NHS has acknowledged a data breach after a BBC investigation found that sensitive personal information about transplant patients — including names, dates of birth, and organ details — was routinely transmitted over an unencrypted pager network.

Why this matters: Transplant patients are not a population with a lot of options. They share deeply sensitive medical details because they have to, trusting that the health system handles it carefully. Sending that data over unencrypted pagers is not a cutting-edge security failure. Pagers have been known to broadcast in the clear for decades. This is a basic, avoidable mistake. The NHS admitted it only after journalists found it. That gap between what institutions know and what patients are told is the accountability problem worth paying attention to here.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
HIPAA Journal · · US Federal

Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents

The Boston Healthcare for the Homeless Program has disclosed a data breach affecting at least 185,000 Massachusetts residents, according to a report that also notes breaches at Monongalia County General Hospital and other healthcare organizations.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
HIPAA Journal · · US Federal

Texas Hearing Institute Ransomware Attack Affects 30,000 Patients

Texas Hearing Institute disclosed a ransomware attack that compromised the protected health information of nearly 30,000 patients. The incident falls under HIPAA breach notification requirements, prompting the organization to go public with details of the cyberattack.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
HIPAA Journal · · US Federal

Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients

Aesto Health, a healthcare technology company based in Birmingham, Alabama, has disclosed a data security incident that affected multiple healthcare provider clients. The breach was reported by The HIPAA Journal, though specific details about the number of patients affected or the nature of the compromised data have not been specified in available reporting.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

RingCentral data breach exposed info of 1.6 million accounts

The ShinyHunters extortion group breached RingCentral in July and stole personal information from 1.6 million accounts, according to data breach notification service Have I Been Pwned.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →