I don't see how both can be true, and I don't know which I would want. On the one hand, the first is highly desirable, but that second use case makes lots of sense, too.
Reading https://developer.apple.com/app-store/review/guidelines/#hea... I think the first isn't entirely true:
"27.5 Apps that share user data acquired via the HealthKit API with third parties without user consent will be rejected"
So, that's not a blanket forbidden. And likely, they aren't preventing anything. That game with an on screen heart rate indicator could easily encrypt heart rate information and send it alongside other data to a game server. It would be hard to detect that.