Ahh, thanks. Should have kept reading. However, a paragraph or so later, it says HIPAA doesn't apply to de-indetified data, and that it's easy for researchers to buy the data set.
Hopefully, some security researchers will get their hands on it, de-anonymize the data set, and then regulators will burn the industry to the ground.