HIPAA explicitly prohibits that kind of demand.
They can get anonymized data as long as it can not personally identify anyone. But the actual records only are exchanged between health care providers directly involved in the care of that individual and other health care providers. Much of the insurance information is also anonymized with case numbers and not names.
So this is blatantly illegal.
Yes, I know they do that. And I hope that fucker lives long enough to be thrown into prison for what he's doing.