One can only implement a HIBP check when one has access to the user's unhashed password. So, at login, registration, and password reset.
Sorry, I still don't understand the procedure you mentioned and I'm genuinely curious.
So, the procedure you need to implement is, on login/registration/pw reset, you SHA-1 hash the user's unhashed password and do a indexed lookup on your copy of HIBP's database. Or if you don't want to maintain that copy, you can use HIBP's API to do something similar.