I do not think Apple has stated it's reasoning for why Health data are device-locked. So, the HIPAA defense may just be a guess. Regardless, the OP is right-- it is silly. Activity and fitness data are not controlled by HIPAA. So this data problem is just poor design and architecture.