"This may seem like a quaint concern when looking into whether one's email address and password have already been exposed online. But it may matter to some."
Surely the idea is to avoid exposing your email address if it hasn't already been exposed?
The HIBP site is presumably OK since so many people will have checked it, but the extra security doesn't hurt and just may avoid letting a previously clean address out into the wild.
As a for instance, I use different emails for each company I buy from, so if it escapes I can be sure it's that company as nobody else knows it - but can I still be sure if I've also sent it to other sites? And I certainly don't want to expose the very complex address I use for banking, which any phisher would first have to guess.