I believe what the doc is doing falls into one of those very gray areas of HIPAA. If he's not sharing identifiers it probably isn't a violation, however, it is darn unprofessional.
Even were it a clear and direct violation I doubt you would be legally liable.
If you haven't already done so check out:
http://www.hhs.gov/ocr/hipaa/