"I will report her anonymously" yes! Good for you op!
She's behaved appallingly AND ILLEGALLY.
I'd be ditching the "friend" too, nasty gossipy piece of work!
"how would they proove anything?" The systems are set up so that there's an electronic trail of who's looked at what. Her employers will know whose medical records she had legitimate reasons to look at and those she didn't she will get in trouble for.
And she's discussing that she's seen info on sexual assault?! For the love of god get this insensitive bitch reported ASAP!!
"If she is blatantly boasting about accessing records what’s to stop her discussing what she’s found." She's already doing that!
Who was there when she mentioned this? Because tbh it sounds like she was letting someone know she knew about their assault! That is utterly vile behaviour!
I'd be concerned she's using the info against people!
At the very least you could send a paper letter stating her name and the names of the people (including yours) who's records she claimed to illegally view. The hospital can then investigate using the methods myself and others have stated are available to her employers. Or an anon phone call.
I'm glad to hear that tech is now starting to be used that can flag such breaches without a report or audit being necessary. Hopefully these will be implemented everywhere ASAP.
Encrypting names could lead to medical issues. Few people would correctly remember a ref number but we remember our names. This is why eg on drug rounds patients are asked or tags checked to reconcile name, dob etc