It is more of misuse than a breach. The data was provided to a guy for academic research, but the guy sold it to a third party. That is where the 'breach happened.
Imagine a clinic has a policy that allows patient data to be released to non-patients but a court decides that the use violates HIPPA. There would be no technical breach of security, but rather a breach of responsibility.