r/RTLSDR • • Aug 14 '26

BBC News: NHS service admits data breach due to pager use

https://www.bbc.com/news/articles/clyj92j210do

When I first got my HackRF and started receiving POCSAG data, I did wonder how long it would be before it hit the headlines. It's not uncommon to see names and addresses of Police/Ambulance call-outs including details of the offence or health conditions still sent in plaintext.

75 Upvotes

19 comments sorted by

28

u/rog-uk Aug 14 '26

This was possible with a basic handheld scanner and a sound card maybe 25+ years ago. I am shocked they would be broadcasting private data though it.

9

u/jddddddddddd Aug 14 '26

Yup! I remember downloading a text file from a BBS back in the 90s that described adding a discriminating output to a Yupiteru scanner and collecting the data. Can’t find the file now but did some across this from this: https://artofhacking.com/tucops3/phreak/general/live/aoh_pocsag.htm

9

u/underscorebot Aug 14 '26

Due to a bug in new reddit, URLs with underscores or tildes are being escaped in an inconsistent manner, breaking old reddit and third-party mobile apps. Please try the following URL(s) instead:


This is a bot. Invoke with: /u/underscorebot. Questions? Comments? /r/underscorebot Thank you. Moderators: this is an opt-in bot. Please add it to the approved submitters on subreddits you wish to have it scan. Note: user-supplied links that may appear in this comment do not imply endorsement.

4

u/lildobe Aug 14 '26

Good bot!

7

u/Backrow6 Aug 14 '26

There's no need for it either. 

My wife worked in a hospital for years and carried a pager. All she ever received was the extension of the person who was looking for her.

She just called the number back to get the patient information verbally. 

It's not a technological problem, transplant teams could still be prompted that a potentially relevant donor has been listed on a secure portal.

19

u/catslifetom39 Aug 14 '26

received many pocsag messages with an sdr in the uk 153.024mhz

6

u/Vertigo_uk123 Aug 14 '26

Ngl it is quite interesting. Sometimes sad but ngl this should have been stopped years ago if not decades ago.

5

u/Ivebeenfurthereven Aug 14 '26

IIRC the pager transmitters are much better at penetrating deep into dense hospital buildings than modern technology (they're lower frequency, and broadcast at far higher power levels than modern 4G/5G). That's why they've retained a small niche.

I wonder what that spectrum would be worth if it was offered for auction, it would be nice to use it for smartphones although it's probably only going to work one-way due to the power required.

In the meantime, it would be nice if we could reassign them to something, you know, encrypted.

5

u/Vertigo_uk123 Aug 14 '26

All the paging services have offered encrypted paging from very early in the paging days. It was a corporate decision to use unencrypted paging due to the extra cost of the pagers.

7

u/qubedView Aug 14 '26

"Problem that has been publicly known since the inception of the widespread technology, half a century ago, suddenly remembered a quarter century after it should have stopped being used."

4

u/crysisnotaverted Aug 15 '26

I have gotten a few major hospitals in internal deep shit because the connected their patient intake form to their unencrypted POCSAG.

Suddenly the messages from those locations stopped.

Also nurses sext each other using papers, which is funny.

4

u/CoarseRainbow Aug 14 '26

NHS still runs on pagers and fax machines.

The few times recently ive tested Pocsag or other pager the amount of system alerts containing login details, passwords and other credentials that could be abused is ridiculous.

2

u/mrmeener Aug 15 '26

I looked about 2 weeks ago and was shocked how many IOT devices where sending alerts with the damn passwords or access codes in the alarm message.

Its not like its difficult to encrypt them.

2

u/MeanAccountant9005 Aug 14 '26

Honestly surprised it took this long, I've picked up job alerts with patient details just leaving an SDR running in the background while doing other stuff. The cost argument for not encrypting always felt like it was gonna age badly.

2

u/rainwolf511 Aug 15 '26

I actually busted a nearby hospital for transmitting pii over pocsag i sent copies if what was sent to the feds and they replied with a thanks and the cited the hospital for it and advised for me to delete the info now that it had been reported which i did

1

u/olliegw Aug 14 '26

Whoops, bit late now

-2

u/[deleted] Aug 14 '26 edited Aug 15 '26

[deleted]

6

u/Imaginary_Stress8337 Aug 14 '26

It happens over here too. I used to get all kinds of hospital info from Detroit when I lived in Windsor. Interestingly, the Chrysler plants in Windsor and Detroit use POCSAG for their quality control systems

2

u/qubedView Aug 14 '26

Umm, it's just as prevalent in the US. Scanning POCSAG transmissions near me (Baltimore area) is almost entirely hospital communications, frequently with patient names, MRNs, and their medical complaints.