I used to work (retired now) for a public service. We could access anyone's details in the UK through our computer terminals.
Lesson number one on induction was if you ever search for a person's details, it will be logged and unless you have no legitimate business reason for the access, you will be sacked. No if's no buts no maybes.
As a manager, every day I would get a read out of whose accounts had been accessed, and by who. If any access seemed odd (accessing people out of our area, accessing people who shared a name with a member of staff ect) they would be highlighted and I would have to check why the account was accessed.
I would also have to find out why a,% of cases not highlighted had been accessed.
And yes, my regional manager would get similar reports about what we, their area mangers, were accessing.
I'm gobsmacked that your trust didn't take this issue seriously.