The progression of medical research depends on access to sensitive health data, creating an inherent tension between patient privacy and public health. National and local policy in the US mandates protection of patient privacy, but largely leaves medical researchers room for interpretation on how to do so. While there may be privacy-preserving mechanisms that could suit medical researchers, we recognize a gap between the security and privacy community and the medical research community: we do not know how medical researchers protect the privacy of their data in practice, what barriers they face in doing so, and how privacy inhibits research. To understand these underlying privacy tensions, we conducted semi-structured interviews with sixteen researchers who either analyzed medical datasets or served as data custodians. We find that medical researchers interpret and implement privacy regulation with deep respect for patient privacy. However, these privacy protections impede or conflict with research needs and productivity throughout the research lifecycle. Sometimes researchers are able to resolve the tensions with bespoke or commercial tools (e.g., by using their own heuristics for data de-identification), whereas other times privacy tensions remain unresolved. We offer recommendations to tool developers, policy-makers, and privacy researchers for building privacy-enhancing tools for medical research.