Future of Biometrics in Healthcare: What Courts Say Now
Here's something that will probably surprise you: a company can scan your face, map your features, and collect detailed measurements of your eyes and cheekbones, all in the name of helping you pick out a pair of glasses, and a federal court just said that is not a healthcare activity. Not even close.
Biometric privacy law doesn't care what industry you're in, it cares why your face was scanned and whether you were properly told. "Healthcare-adjacent" is not a free pass.
Most people assume there's a kind of invisible force field around anything health-related. Doctor's office? Protected. Eye exam? Covered. Eyeglass store with a virtual try-on tool? Surely that counts as medical, right? A 7th Circuit federal court, one step below the Supreme Court, just said: no. And the reasoning is worth understanding, because it changes how you should think about every biometric (body-measurement) scan you agree to from here on out.
The BIPA Case That Cracked the Assumption Open
The company at the center of this story is Gunnar Optiks, a brand that makes specialty eyewear. Their website featured a virtual try-on tool, the kind where you let your camera map your face so you can see how different frames look on you. Convenient, right? Fun, even.
The legal problem: Illinois has a law called BIPA, the Biometric Information Privacy Act, that requires companies to tell you, in writing, exactly what biometric data (your face measurements, fingerprint geometry, iris patterns, body information that is uniquely yours) they are collecting, why they're collecting it, and how long they plan to keep it. Before they collect anything. BIPA also requires your written consent. Skip those steps, and you're in legal trouble in Illinois.
Gunnar argued their try-on tool was healthcare-related, because glasses correct vision, and vision is health. Therefore, they said, BIPA's healthcare exemption applied and they didn't need to follow the consent rules. It sounds almost reasonable, until you hear what the judge said back. This article is part of a series, start with Your Face Was Scanned Saturday Nobody Asked If That Was Lega.
"Better-appearing glasses are not medical treatment." Judge Frank Easterbrook, DiCello Levitt LLP case analysis
Four words. That's all it took to cut through the argument. The virtual try-on tool was about aesthetics, how the frames look on your face, not about treating an eye condition. The court called it exactly what it was: a shopping feature. A nice one, but a shopping feature.
What the BIPA Eyewear Healthcare Ruling Actually Means
This is where most people, and honestly, a lot of businesses, get confused. The exemption exists for real reasons. Hospitals legitimately need to collect biometric data. Pharmacies use fingerprint scans to verify that the right person is picking up a controlled medication. That's a genuine healthcare use, tied to patient safety and federal HIPAA rules.
HIPAA, the Health Insurance Portability and Accountability Act, is the federal law that governs how medical information gets handled. Think of it as the strict rulebook that doctors, hospitals, and insurers all have to follow to protect patient data. It's detailed, demanding, and carries real penalties.
Here's the part that matters: Sidley Austin LLP's analysis of Illinois Supreme Court precedent makes clear that to qualify for BIPA's healthcare exemption, a company must actually comply with HIPAA itself. Not just work in a health-adjacent industry. Not just sell a product that some people use for their health. They must be subject to HIPAA's rules and follow them.
Gunnar Optiks is an eyewear retailer. They don't treat patients. They don't file insurance claims for medical procedures. They are not a HIPAA-covered entity, which means the healthcare exemption simply doesn't apply to them, no matter how vision-related their product is.
That number is growing fast. What started as an Illinois problem for companies is now a multi-state compliance reality. And every one of those laws will eventually face the same question the 7th Circuit just answered: does working near healthcare count as being healthcare? Courts are consistently saying no. Previously in this series: Your Selfie Isnt A Photo Anymore Its A Math File That Never .
Why People Misread the Gunnar Optiks Privacy Ruling
Look, the confusion here is completely understandable. We've been trained to think in categories, healthcare stuff gets privacy protection, retail stuff doesn't. And that's mostly true! But BIPA doesn't organize the world by industry. It organizes it by purpose and process.
Think of it like airport security. Walking into an airport doesn't automatically get you onto a plane. You have to qualify, show your boarding pass, go through screening, prove you're actually there to fly. The building doesn't grant you access; your specific purpose and your willingness to follow the rules do.
The healthcare exemption works the same way. Being in or near the healthcare world is like walking into the airport. You still have to prove your actual purpose is medical, tied to HIPAA-defined treatment, payment, or healthcare operations, and you still have to follow HIPAA's rules to get through. Browse the gift shop (or help someone pick out stylish frames), and you don't get to board the plane just because you're inside the terminal.
Where people go wrong is conflating the product category with the legal purpose. Eyeglasses correct vision. Vision is health. Therefore eyeglasses are healthcare. It sounds airtight, right up until a federal judge points out that the scan happened to show you how frames look on your face, not to diagnose astigmatism or prescribe lenses. The purpose was aesthetic. The exemption was gone.
The same logic applies in less obvious places. As Sheppard Mullin notes in its analysis of 7th Circuit rulings, even employee biometrics collected inside a hospital don't automatically qualify for the healthcare exemption. If a nurse scans their fingerprint to clock in for a shift, that's timekeeping, not a HIPAA-defined healthcare operation. The setting is a hospital. The purpose is payroll. Those are different things, and courts are paying attention to the difference.
What Real Biometrics in Healthcare Actually Looks Like
It helps to see the other side of the line, the cases where biometrics in healthcare really is what it claims to be. A hospital that uses fingerprint scans to confirm patient identification before surgery is using biometric authentication for a treatment purpose. A pharmacy verifying that the correct patient is picking up a controlled prescription is doing the same thing. These are textbook examples of biometric systems built around patient safety, not convenience or marketing.
The difference between these cases and the Gunnar Optiks situation comes down to purpose. Patient identification tied to treatment, payment, or healthcare operations is exactly what the HIPAA-linked exemption was written to cover. A biometric scan used to sell a product, even a health-adjacent product like eyeglasses, is not. Efficiency for a hospital's check-in line is not the same legal category as efficiency for an online shopping cart, even though both might use the word "biometric" to describe the technology.
Why Patient Identification Raises the Compliance Bar
Patient identification is one of the most common uses of biometrics in healthcare, and it's also one of the most tightly regulated. When a clinic collects a fingerprint or face scan to confirm patient identity, that data has to be stored securely, used only for the stated purpose, and protected under the same HIPAA safeguards that cover the rest of a patient's medical record. Biometric authentication used this way is not exempt from oversight, it is subject to a different, stricter set of rules than a general commercial BIPA notice.
This matters because patient identification errors carry real consequences, the wrong medication, the wrong chart, the wrong procedure. Biometric systems exist in healthcare settings precisely to reduce that risk, which is why hospitals invest heavily in secure biometric authentication rather than relying on names and birthdates alone. The security bar is higher because the stakes are higher, not because the industry gets a free pass on consent and disclosure.
How Biometric Systems Balance Security and Patient Trust
A well-run biometric system in a hospital or clinic has to do two things at once: verify identity quickly and keep the underlying data secure. That balance is harder than it sounds. Biometric data like fingerprints and face geometry can't be reset the way a password can, so a breach involving healthcare biometrics carries long-term risk for the patient, not just short-term inconvenience.
That's why legitimate biometric authentication in healthcare comes bundled with strict data management rules, encryption, access limits, retention schedules, and audit trails. A company that wants to claim the healthcare exemption under BIPA has to show this kind of security and management infrastructure actually exists, not just that it operates somewhere near a hospital or an eye doctor's office.
The Efficiency Argument Doesn't Replace the Consent Requirement
Many companies point to efficiency as the reason biometrics make sense, faster checkout, faster check-in, faster identity verification. Efficiency is a real benefit of biometric systems, and it's part of why hospitals, pharmacies, and clinics keep adopting them for patient identification. But efficiency is not a legal substitute for consent, and it never has been under BIPA.
Whether a business is in healthcare or retail, the requirement is the same: tell people in writing what biometric data is being collected, why, and how long it will be kept, then get their written consent. A faster line at checkout doesn't change that. A faster check-in at a clinic doesn't change that either. Efficiency explains why biometrics in healthcare are attractive to build; it doesn't explain away the disclosure a company owes the person being scanned.
What You Were Actually Supposed to Be Told
Here's the baseline that BIPA sets, regardless of any exemption. Before a company captures your biometric data, they must inform you in writing about two things: the specific purpose for collecting it, and how long they plan to keep it. Then they need your written consent. This isn't buried in a terms-of-service paragraph. It's supposed to be clear, upfront, and separate. Up next: Monroe County Biometric Disclosure Retail Facial Recognition.
That requirement exists because biometric data is different from a password or a credit card number. You can change your password. You cannot change your face, your iris pattern, or the geometry of your fingerprint. Once that data is collected, stored, and potentially exposed, the risk is permanent in a way that most data breaches aren't. That's the whole reason Illinois passed BIPA in the first place, and why the healthcare exemption was always meant to be a narrow carve-out, not a wide-open door.
Where Biometric Technology Fits Into Everyday Care
Biometric technology now shows up in far more places than a hospital operating room. Clinics use it for patient identification at check-in, pharmacies use it to confirm who is picking up a prescription, and some health systems use it to secure staff access to medication rooms. Each of these uses biometric technology for a specific, documented purpose tied to care or safety, not for marketing convenience.
What separates lawful biometric technology from a legal problem is the paperwork behind it. A clinic using biometric technology for patient identification should be able to explain what data it collects, how long it keeps it, and who else can see it. If a business can't answer those questions plainly, the technology itself isn't the issue, the missing disclosure is.
Fingerprint Identification and Why Hospitals Still Rely on It
Fingerprint identification remains one of the simplest and most trusted tools in healthcare settings, precisely because it's fast and hard to fake. A pharmacy might use fingerprint identification to confirm that the person picking up a controlled substance is actually the patient named on the prescription. A hospital might use fingerprint identification to control staff access to secure medication storage areas.
The reason fingerprint identification survives legal scrutiny in these settings is that the purpose lines up with treatment, payment, or healthcare operations. That's a very different footing than a retailer using a fingerprint or face scan to speed up checkout, where no HIPAA-covered activity is happening at all.
Biometric Solutions Built for Healthcare Compliance
Not every biometric solution on the market is designed with HIPAA in mind, and that gap is exactly where companies get into trouble. A biometric solution built for a health system typically includes encryption standards, access logging, and retention limits baked into the product from the start, because vendors know a hospital client will be audited on those points.
A biometric solution designed for retail convenience, by contrast, is usually built around speed and customer experience, not healthcare-grade data handling. Buying a biometric solution off the shelf and dropping it into a clinical workflow without checking how it stores and protects data is a common and costly mistake.
Recognizing the Line Between Health Products and Health Operations
Facial recognition and fingerprint recognition tools are also spreading into wellness apps, fitness trackers, and supplement subscriptions, products that talk about health constantly without ever becoming HIPAA-covered operations. Recognition technology used to log a workout or personalize a wellness plan is not the same as recognition technology used to confirm a patient's identity before a medical procedure. The word "biometric" doesn't change categories; the purpose behind the recognition does.
This is exactly the kind of recognition confusion that tripped up Gunnar Optiks. A try-on tool using facial recognition to preview eyewear styles is still, at its core, a shopping aid. Recognition technology aimed at aesthetics doesn't graduate into a healthcare operation just because the product sitting on your face happens to correct your vision.
What Staff Should Know Before Using Biometric Systems on the Job
Staff in clinics, pharmacies, and hospitals increasingly interact with biometric systems themselves, not just as something used on patients. A nurse clocking in with a fingerprint scan, or staff badge-swapping for a fingerprint badge to access a secure ward, are common examples. As earlier sections noted, that kind of staff-facing biometric use is usually timekeeping or access control, not a HIPAA-defined healthcare operation, even though it happens inside a hospital.
Employers who roll out biometric systems for staff should still give written notice about what's collected and why, separate from any patient-facing biometric authentication used for identification. Treating staff biometrics and patient biometrics as the same legal category is a mistake that has already led to lawsuits outside the healthcare context, and there's no reason to expect hospitals get an automatic pass just because the setting is medical.
What You Just Learned
- 🧠Setting ≠purposeBeing near healthcare doesn't make a biometric scan a healthcare activity. Courts look at why the data was collected, not what building you were in.
- 🔬 The exemption has a double lockTo skip BIPA's consent rules, a company needs the right purpose (treatment/payment/operations) AND must actually comply with HIPAA. One without the other doesn't work.
- 📋 Consent comes first, alwaysWritten notice about purpose and retention, plus written consent, is the baseline. Exemptions are the exception, not the default.
- 🧠This is spreading fastAbout 20 states now have biometric privacy laws. What happens in Illinois courts shapes how companies handle your face data everywhere.
A biometric scan isn't automatically safe or exempt just because it happens in a medical-adjacent setting. The law asks: what exactly was collected, why, who can access it, and were you properly told? If you weren't given clear written notice before the scan happened, regardless of the industry, that's a problem worth knowing about.
At CaraComp, we spend a lot of time thinking about exactly this kind of distinction, where facial and biometric data gets collected, what it's actually used for, and how the gap between "we're healthcare-adjacent" and "we follow healthcare rules" can swallow someone's privacy whole. The Gunnar ruling is a useful case study because it makes the line visible.
So next time you're about to let a website or app scan your face, even a friendly, try-on-glasses kind of scan, ask yourself: did anyone tell you in writing what they're collecting, why, and when they'll delete it? If the answer is a vague checkbox buried in fine print, you now know exactly what question to push back with.
Because "we're kind of medical" and "we follow the rules that protect your medical data" are two entirely different things. A federal judge just said so. In four words.
Understanding biometrics in healthcare means understanding this line between purpose and setting. A biometric scan used for patient identification, tied to treatment or payment, sits on one side of the line. A biometric scan used to sell glasses, luggage, or anything else sits on the other, no matter how healthy the product claims to be. Biometric authentication only earns special legal treatment when the underlying activity is genuinely a healthcare operation.
For patients, this distinction has practical value beyond the courtroom. If a clinic asks for a fingerprint or face scan as part of patient identification, it's reasonable to ask how that biometric data will be stored, who can access it, and whether it falls under the same security rules that protect the rest of your medical record. A legitimate healthcare provider should have straightforward answers, because secure handling of biometric data is part of how patient trust and regulatory compliance work together.
For businesses building biometric systems anywhere near the healthcare space, the Gunnar ruling is a warning about assuming too much. A wide range of products touch health in some loose sense, supplements, fitness trackers, eyewear, wellness apps, but touching health is not the same as being a HIPAA-covered healthcare operation. Biometric authentication baked into any of these products needs its own BIPA-compliant consent process unless the company can show it genuinely meets HIPAA's definition of treatment, payment, or healthcare operations.
The broader lesson extends past eyewear. As biometric systems keep spreading into patient identification, security checkpoints, workplace timekeeping, and retail convenience, the question courts keep asking is the same one Judge Easterbrook asked about Gunnar Optiks: what was this scan actually for? Biometrics in healthcare earn their exemption through function, not proximity, and that standard isn't likely to loosen as more states pass their own biometric privacy laws.
Digital record systems now sit right next to biometric identification in most clinics, which means healthcare biometric data rarely stands alone, it usually links to a digital chart, a digital prescription history, or a digital scheduling system. That linkage is part of why security and access controls matter so much: a compromised biometric system doesn't just expose a fingerprint, it can open a path into the digital record it's tied to. Healthcare biometric deployments that skip this connection when planning security are leaving an obvious gap open.
Access to secure areas inside a hospital or pharmacy is another place biometric authentication is quietly doing real work. Staff badges paired with a fingerprint or face scan can control access to medication storage areas, records rooms, and other restricted areas without slowing down people who legitimately need to get in and out all day. Limiting access this way is a security measure, not a patient identification tool, so it's usually justified under different rules than the ones covering patient-facing biometric authentication.
Data Privacy Expectations Are Shaping the Future of Biometrics in Healthcare
Data privacy is the thread running through every part of this story, and it's also the thread that will shape the future of biometrics in healthcare as more states pass their own versions of BIPA. A hospital or clinic that treats data privacy as a checkbox exercise today is setting itself up for the same problem Gunnar Optiks ran into, a biometric program that works fine technically but skips the disclosure step that the law actually requires. As more health systems adopt biometric authentication for patients, data privacy expectations are only going to get stricter, not looser.
Healthcare Biometrics Is Moving From Novelty to Infrastructure
Healthcare biometrics started as a handful of pilot programs, a fingerprint scanner at a pharmacy counter, a face-match tool at a hospital kiosk. That's changing. Healthcare biometrics is increasingly treated as core infrastructure, tied into scheduling, records, and payment systems rather than sitting off to the side as an experiment. That shift raises the compliance bar, because infrastructure-level healthcare biometrics touches far more patient data than a single standalone scanner ever did.
Patients are the people this entire framework is meant to protect, and it's worth saying plainly: patients have the right to ask what's collected before any scan happens. Patients who understand the difference between a HIPAA-covered biometric use and a commercial one are better equipped to ask the right questions at check-in. That knowledge doesn't require a law degree, it just requires knowing that "medical-adjacent" and "medically exempt" are not the same thing.
Looking ahead, the future of biometrics in healthcare will likely involve more emerging technologies layered on top of the fingerprint and face-scan tools already in use, iris scanning, vein-pattern recognition, and voice-based patient identification are all moving from research settings into pilot deployments. Each new scanner or sensor that enters a clinical workflow adds another point where security and consent both have to hold up, which is exactly why the legal reasoning in the Gunnar case matters well beyond eyewear.
Biometric technology shows substantial promise for reducing identification errors and speeding up care, but that promise only gets realized if the underlying data privacy and security practices keep pace. A scanner that captures better data doesn't help a hospital if the consent process behind it is an afterthought. The future of biometrics in healthcare depends as much on getting the paperwork right as it does on the hardware improving.
It's also fair to say that healthcare is revolutionizing patient authentication in ways that go beyond simple identity checks, biometric authentication tied to a patient's full digital record can flag allergies, confirm insurance identity, and reduce fraud all at once. That kind of growing biometrics usage across care settings is exactly why the line between genuine healthcare operations and health-adjacent commercial products, drawn so clearly in the Gunnar ruling, will keep mattering as the technology spreads.
Frequently asked questions
What does the future of biometrics in healthcare look like after the Gunnar Optiks ruling?
The future of biometrics in healthcare now depends on purpose, not industry labels. Courts have made clear that scanning a face or fingerprint only counts as a healthcare activity if it ties to HIPAA-defined treatment, payment, or operations, and if the company is actually subject to HIPAA rules. Simply selling a health-adjacent product no longer earns automatic legal protection.
Does a healthcare exemption cover any company that scans biometric data?
No. A federal court ruled that Gunnar Optiks, an eyewear retailer using a virtual try-on tool, could not claim BIPA's healthcare exemption because it is not a HIPAA-covered entity. The judge called the scan a shopping feature about aesthetics, not medical treatment, since it didn't diagnose or treat any eye condition.
Why did the court say scanning faces for glasses isn't a healthcare activity?
The judge stated that better-appearing glasses are not medical treatment, since the tool measured features to show how frames looked, not to diagnose or prescribe. Because Gunnar Optiks doesn't treat patients, file medical insurance claims, or follow HIPAA, the healthcare exemption under BIPA did not apply to their biometric scanning.
