A hospital worker shared a screenshot of a patient's medical record with their partner after accessing up to 200 individual patient records without permission at a Somerset NHS trust, new documents reveal.
Victims told the BBC they are disgusted the worker, who resigned before any disciplinary action, received only a police caution.
Correspondence obtained by the BBC under the Freedom of Information Act suggests patient information may have been shared and that a patient was contacted using a phone number obtained from hospital records.
Somerset NHS Foundation Trust previously said records belonging to up to 200 people were accessed inappropriately between August 2017 and October 2023.
More from Bristol
Investigation and outcome
The breach by the Musgrove Park hospital worker was reported to the Information Commissioner's Office (ICO) in October 2023 and investigated by Avon and Somerset Police.
The ICO said it supported "the allegation of unlawful obtaining of personal data" and concluded appropriate action had been taken.
After confirming it would take no further regulatory action the case was closed.
A spokesperson for Avon and Somerset Police said a woman made full admissions during an interview and was given a conditional caution after officers concluded her actions were not malicious and involved no financial gain.
The breach spanned several years, with audit data showing records were accessed between August 2017 and October 2023.
Those affected included patients as well as people known to the member of staff, including colleagues, friends and family members and their partners.
'She violated families'
The BBC has spoken to a colleague who is one of several staff whose records were accessed and who believes there should have been a prosecution.
They said the worker had discovered someone was pregnant by accessing their records and had viewed files relating to children whose parents had died to find out their cause of death.
Another patient, who wants to remain anonymous, told the BBC: "She didn't just breach data, she violated families, vulnerable people, and even the records of those who aren't alive to defend themselves.
"She went through my medical information, some of which was highly sensitive and my son's, then sent screenshots to her partner. Where's the justice?"
What information was accessed
Documents show the staff member had access to a single hospital system as part of their role.
This allowed them to view demographic information such as names, dates of birth, addresses and GP details, as well as A&E attendances, admission details, wards, consultants and outpatient appointments.
The trust said the system did not include clinical letters, discharge summaries, or separate records for mental health, community or sexual health services.
However, the ICO correspondence suggests the misuse went beyond viewing data, with evidence of information being shared externally.
More than 1,400 serious patient data breaches have been recorded across the NHS in recent years, according to a Freedom of Information request by the Health Service Journal.
Cases have included attempts to obtain and sell the medical records of Catherine, Princess of Wales, 11 staff being dismissed for accessing records linked to the Nottingham attacks victims and workers being sacked after viewing records connected to the Bedford train crash.
And an 'Urgent' probe was reported into patient data access after 40 staff opened files on a boy attacked by a crocodile

The BBC can also reveal that the way hospitals report breaches does not necessarily reflect how many patients were affected.
For example, Somerset NHS Foundation Trust's annual report recorded the incident as one of three data security breaches in 2023, despite up to 200 people being affected.
Annual reports show other NHS trusts in the West have also recorded data security incidents.
Gloucestershire Hospitals NHS Foundation Trust reported 187 information governance breaches in 2024-25, Great Western Hospitals NHS Foundation Trust 48 and North Bristol NHS Trust three incidents reported to the Information Commissioner's Office (ICO). University Hospitals Bristol and Weston NHS Foundation Trust also reported a cyber attack involving a third-party provider handling patient samples.
The trust said it could not confirm whether any of its patients had been affected but reported the incident to the ICO while investigations continued.

The BBC has also spoken to a Bristol man who questioned whether a healthcare worker improperly accessed his wife's medical records after unexpectedly appearing at her bedside at Southmead Hospital.
The man, who asked not to be identified, said his wife had been transferred there at short notice for surgery for incurable cancer and he had not told the healthcare worker where she was being treated.
He said his wife had originally been due to have an operation at Bristol Royal Infirmary, but the procedure was moved to Southmead at short notice and he had not shared details of the new location, ward or bed number.
He told the BBC: "This is impossible unless they snoop into the system."
The man said he complained to ward staff, the Patient Advice and Liaison Service and the trust's data protection team.

He said he was initially told investigators had found no evidence of a data breach, but questioned whether the correct time period had been examined.
He said the unexpected visit left his wife distressed and vulnerable, adding: "She raised a concern that because she's a female, her clothes might not be in the proper place and she wasn't expecting any visitor at that point. She was a bit afraid.
"She's a practising Muslim and she was worried about her religion and all this stuff like that."
He added that after the healthcare worker returned for a second visit,"my wife says, please don't come here without telling my husband."
Bristol NHS Foundation Trust, which runs Southmead Hospital, said it could not comment while its investigation was ongoing.
Glyn Howells, Senior Information Risk Owner (SIRO) and managing director, said: "The trust takes confidentiality of patient information extremely seriously.
"We are committed to ensuring patients' records are only ever accessed where there is a legitimate need.
"We are currently investigating this complaint, and it would be inappropriate to provide any further comment until our investigation is complete."
Calls for NHS record alerts
Sam Smith, from privacy campaign group Med Confidential, said the Taunton case highlighted wider concerns about access to NHS records.
He said staff can often view records across different parts of the health service and that: "the protection is that you shouldn't, not that you can't".
He added there is "very little to stop you" if someone is determined to look up records they have no legitimate reason to access.
Smith said audit trails already record who has viewed a patient's file, but argued patients are rarely told when records have been accessed.
He suggested people should receive automatic notifications through the NHS App when their records are viewed.
Greater transparency, he said, would help deter misuse.
"The only way to prevent abuse is to stop the secrecy that facilitates it."

Trust response
Somerset NHS Foundation Trust previously apologised to those affected, saying patient confidentiality had "not [been] respected" in this case.
Phil Brice, the trust's director of corporate services, said: "We apologise unreservedly to every person whose hospital record has been inappropriately accessed in this way.
"Many NHS professionals need access to confidential information in order to do their jobs effectively... Very sadly, this was not respected in this case."
Get in touch
Tell us which stories we should cover in Somerset
Follow BBC Somerset on Facebook and X. Send your story ideas to us on email or via WhatsApp on 0800 313 4630.