Good advice from past responders.
I work in this area and confirm to either contact PALS at your hospital or the practice manager, if she works at your GP Surgery.
There is an audit trail of username, date and time stamp on every record for most NHS IT systems. This covers edits as well as views of the patient record.
This isn’t actively monitored though, it will make it easier for the teams to check if you provide her name as otherwise they will have a list of potentially 100-1000s of transactions to check through. Most of which I would expect to be legitimate staff views. E.g.If you are booked for a blood test by the GP, to be
collected via the clinic at the hospital, between admin staff, the phlebotomy team and then lab staff who process the samples it could run into 100s for ID check, result history etc before it gets to the final clinician at the GP reviewing the results. That’s a single blood test event. Add in your historic contact it can easily be 1000s.
If for example your friend works in none of these areas it may be identified when you ask, but if she does, the team will be unlikely to be able to investigate anything without you providing her name as she will be within the assumed access group. E.g ‘booking team’ ‘phlebotomy’ or ‘pathology’
It’s covered in staff training at all NHS trusts as part of onboarding, all staff know the line and risk to their employment for breaking the agreement. It will be handled appropriately if you raise it.
Hope that helps!