First, swansong will probably know best here.
But i'm going to wildly take a swing.
I don't think that's entirely true. Doctors can't just go randomly probing medical records. Most of the largest systems log who has seen your records and I'm guessing they audit those. Just because Prince is at your hospital doesn't mean you can open his records and see what happened. You need to have a reason. (I use that case specifically because they fired a bunch of people who viewed his records despite being RNs or maybe even an MD or two)
Yeah, there's no "exclusion" in HIPAA, but as a covered entity (to wit: a healthcare organization) they do in fact have a "need-to-know" reason to access your medical history. I'm not sure about specialties like ophtalmologists (do they really need to know your vaccination status? I don't honestly know) and access to unrelated PHI, but I can say that our hand surgeons and phsyical therapists can access your whole chart. We may re-order things so that they're presented with specialty-specific info, but they can definitely access more. It is possible that this eye doctor's practice had very strict interpretations of HIPAA and that they were just exercising that.
A doctor would be violating HIPAA if they just opened up some rando's chart, but that sort of violation happens literally millions of times per day across the country. It only becomes a problem if it... becomes a problem. Like when dozens of idiots were fired for looking up Jussie Smollett's chart after his "incident".
https://www.midlandhealth.org/Uploa...ompliance/Compliance Connection July 2019.pdf
Best practice is to stay the f out of charts where you don't belong.