I wonder what they saw on their screen. Maybe it was nothing and the tech just enjoyed being unhelpful and was maybe rewarded for it. Maybe it was flagged by NSA heuristics and there was an "untrustworthy" message.
Nope, the guy said that "yes, the appleid is banned, you know why, you breached our T&Cs, no you can't restore it".
He rejected to specify what rule exactly was breached.
That seems like a strange analogy, since as far as I know HIPAA is designed to prevent sharing private data with outsiders and should not prevent you from accessing your own data.
I've heard plenty about how HIPAA gets in the way of legitimate sharing with outsiders (e.g. making a common format for medical profile transfer impractical), but I don't recall having heard about it preventing the principal individual from getting answers from their own provider.