They don't have to know anything about the specific person to correlate data they likely already have in their POS system.
Can’t? Really?
Maaaybe it’s against some law or privacy policy or mandatory annual training.
But do you honestly believe companies follow laws and policies if they think they can get away with not?
And even if you can ignore that corporations are regularly -publicly- wrist-slapped for failings in those areas and still believe they are virtuous, privacy-respecting, law-abiding entities (rofl) … are you ready to argue that no executive or other employee ever, (knowingly or unknowingly) uses data to run a calculation or check a theory against published policy?
The only thing that surprises me about the above scenarios is there’s a human alive who would believe their improbabl3a let alone, as “can’t” would imply, impossible.
I think HIPAA is the sort of thing where if you hear about it then it's taken seriously, but the overwhelming number of violations are just ignored and you never hear about them. I'd like to be wrong but unfortunately that's the information I've been fed by people more knowledgeable than me.