You don't say who told you.
Just because some unknown person told you it was against HIPAA laws doesn't mean that the person was correct.
It could be that they really have no idea what they are talking about.
Here's a summary of the privacy provisions that are covered by HIPAA:
The HIPAA Privacy Rule
The HIPAA Privacy Rule establishes national standards to protect individuals’ medical records and other personal health information and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically. The Rule requires appropriate safeguards to protect the privacy of personal health information, and sets limits and conditions on the uses and disclosures that may be made of such information without patient authorization. The Rule also gives patients rights over their health information, including rights to examine and obtain a copy of their health records, and to request corrections.
Were you looking at patient's confidential medical records?
It would appear that your source is misinformed as to what is covered by HIPAA.