Volunteers or not, they have to follow HIPAA protocols. The hospital is liable for all actions of their representatives, that includes contractors, volunteers, students, clergy etc whether they are paid or not.
It doesn't matter what happens to the victim as a result, if anyone representing the hospital discloses any medical information to another elder or the organization, they're in violation of HIPAA protocols.
In the EU it probably would be a GDPR violation and the UK has similar provisions. Although public healthcare doesn't necessarily offer bloodless solutions as they are too expensive. I know back in the day there were private hospitals in the EU that would do this, but it was pricey.