The Harvard researcher probably fell under research for public health. I'd hope private researchers can access public health data. The goal for "ICD" global standardized diagnoses codes is to help research.
There are rules for distribution and compliance that should carry over to each handler of the data sets.
Given all that, I still have anxiety of bad actors handling the private information.