That is a violation, if it is done for non business needs. You can report the violation to the HIPAA board, who may choose to issue a retraining memo to the offending department or company. If you have not suffered any specific financial damages, you have no basis for a lawsuit.