"Better-Appearing Glasses Are Not Medical Treatment": The 4 Words That Just Changed Your Face-Scan Rights
Here's something that will probably surprise you: a company can scan your face, map your features, and collect detailed measurements of your eyes and cheekbones — all in the name of helping you pick out a pair of glasses — and a federal court just said that is not a healthcare activity. Not even close.
Biometric privacy law doesn't care what industry you're in — it cares why your face was scanned and whether you were properly told. "Healthcare-adjacent" is not a free pass.
Most people assume there's a kind of invisible force field around anything health-related. Doctor's office? Protected. Eye exam? Covered. Eyeglass store with a virtual try-on tool? Surely that counts as medical, right? A 7th Circuit federal court — one step below the Supreme Court — just said: no. And the reasoning is worth understanding, because it changes how you should think about every biometric (body-measurement) scan you agree to from here on out.
The Case That Cracked the Assumption Open
The company at the center of this story is Gunnar Optiks, a brand that makes specialty eyewear. Their website featured a virtual try-on tool — the kind where you let your camera map your face so you can see how different frames look on you. Convenient, right? Fun, even.
The legal problem: Illinois has a law called BIPA — the Biometric Information Privacy Act — that requires companies to tell you, in writing, exactly what biometric data (your face measurements, fingerprint geometry, iris patterns — body information that is uniquely yours) they are collecting, why they're collecting it, and how long they plan to keep it. Before they collect anything. BIPA also requires your written consent. Skip those steps, and you're in legal trouble in Illinois.
Gunnar argued their try-on tool was healthcare-related, because glasses correct vision, and vision is health. Therefore, they said, BIPA's healthcare exemption applied and they didn't need to follow the consent rules. It sounds almost reasonable — until you hear what the judge said back. This article is part of a series — start with Your Face Was Scanned Saturday Nobody Asked If That Was Lega.
"Better-appearing glasses are not medical treatment." — Judge Frank Easterbrook, DiCello Levitt LLP case analysis
Four words. That's all it took to cut through the argument. The virtual try-on tool was about aesthetics — how the frames look on your face — not about treating an eye condition. The court called it exactly what it was: a shopping feature. A nice one, but a shopping feature.
So What Does the Healthcare Exemption Actually Require?
This is where most people — and honestly, a lot of businesses — get confused. The exemption exists for real reasons. Hospitals legitimately need to collect biometric data. Pharmacies use fingerprint scans to verify that the right person is picking up a controlled medication. That's a genuine healthcare use, tied to patient safety and federal HIPAA rules.
HIPAA — the Health Insurance Portability and Accountability Act — is the federal law that governs how medical information gets handled. Think of it as the strict rulebook that doctors, hospitals, and insurers all have to follow to protect patient data. It's detailed, demanding, and carries real penalties.
Here's the part that matters: Sidley Austin LLP's analysis of Illinois Supreme Court precedent makes clear that to qualify for BIPA's healthcare exemption, a company must actually comply with HIPAA itself. Not just work in a health-adjacent industry. Not just sell a product that some people use for their health. They must be subject to HIPAA's rules and follow them.
Gunnar Optiks is an eyewear retailer. They don't treat patients. They don't file insurance claims for medical procedures. They are not a HIPAA-covered entity — which means the healthcare exemption simply doesn't apply to them, no matter how vision-related their product is.
That number is growing fast. What started as an Illinois problem for companies is now a multi-state compliance reality. And every one of those laws will eventually face the same question the 7th Circuit just answered: does working near healthcare count as being healthcare? Courts are consistently saying no. Previously in this series: Your Selfie Isnt A Photo Anymore Its A Math File That Never .
Why People Get This Wrong (And It's Not Stupid That They Do)
Look, the confusion here is completely understandable. We've been trained to think in categories — healthcare stuff gets privacy protection, retail stuff doesn't. And that's mostly true! But BIPA doesn't organize the world by industry. It organizes it by purpose and process.
Think of it like airport security. Walking into an airport doesn't automatically get you onto a plane. You have to qualify — show your boarding pass, go through screening, prove you're actually there to fly. The building doesn't grant you access; your specific purpose and your willingness to follow the rules do.
The healthcare exemption works the same way. Being in or near the healthcare world is like walking into the airport. You still have to prove your actual purpose is medical — tied to HIPAA-defined treatment, payment, or healthcare operations — and you still have to follow HIPAA's rules to get through. Browse the gift shop (or help someone pick out stylish frames), and you don't get to board the plane just because you're inside the terminal.
Where people go wrong is conflating the product category with the legal purpose. Eyeglasses correct vision. Vision is health. Therefore eyeglasses are healthcare. It sounds airtight, right up until a federal judge points out that the scan happened to show you how frames look on your face — not to diagnose astigmatism or prescribe lenses. The purpose was aesthetic. The exemption was gone.
The same logic applies in less obvious places. As Sheppard Mullin notes in its analysis of 7th Circuit rulings, even employee biometrics collected inside a hospital don't automatically qualify for the healthcare exemption. If a nurse scans their fingerprint to clock in for a shift, that's timekeeping — not a HIPAA-defined healthcare operation. The setting is a hospital. The purpose is payroll. Those are different things, and courts are paying attention to the difference.
What You Were Actually Supposed to Be Told
Here's the baseline that BIPA sets — regardless of any exemption. Before a company captures your biometric data, they must inform you in writing about two things: the specific purpose for collecting it, and how long they plan to keep it. Then they need your written consent. This isn't buried in a terms-of-service paragraph. It's supposed to be clear, upfront, and separate. Up next: Monroe County Biometric Disclosure Retail Facial Recognition.
That requirement exists because biometric data is different from a password or a credit card number. You can change your password. You cannot change your face, your iris pattern, or the geometry of your fingerprint. Once that data is collected, stored, and potentially exposed, the risk is permanent in a way that most data breaches aren't. That's the whole reason Illinois passed BIPA in the first place — and why the healthcare exemption was always meant to be a narrow carve-out, not a wide-open door.
What You Just Learned
- 🧠 Setting ≠ purpose — Being near healthcare doesn't make a biometric scan a healthcare activity. Courts look at why the data was collected, not what building you were in.
- 🔬 The exemption has a double lock — To skip BIPA's consent rules, a company needs the right purpose (treatment/payment/operations) AND must actually comply with HIPAA. One without the other doesn't work.
- 📋 Consent comes first, always — Written notice about purpose and retention, plus written consent, is the baseline. Exemptions are the exception, not the default.
- 🧠 This is spreading fast — About 20 states now have biometric privacy laws. What happens in Illinois courts shapes how companies handle your face data everywhere.
A biometric scan isn't automatically safe or exempt just because it happens in a medical-adjacent setting. The law asks: what exactly was collected, why, who can access it, and were you properly told? If you weren't given clear written notice before the scan happened — regardless of the industry — that's a problem worth knowing about.
At CaraComp, we spend a lot of time thinking about exactly this kind of distinction — where facial and biometric data gets collected, what it's actually used for, and how the gap between "we're healthcare-adjacent" and "we follow healthcare rules" can swallow someone's privacy whole. The Gunnar ruling is a useful case study because it makes the line visible.
So next time you're about to let a website or app scan your face — even a friendly, try-on-glasses kind of scan — ask yourself: did anyone tell you in writing what they're collecting, why, and when they'll delete it? If the answer is a vague checkbox buried in fine print, you now know exactly what question to push back with.
Because "we're kind of medical" and "we follow the rules that protect your medical data" are two entirely different things. A federal judge just said so. In four words.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
That "Try On Glasses" Button Just Mapped Your Face 468 Ways
You think you're using a fun shopping feature. A federal court says you may be sharing regulated biometric data. Learn what's actually happening when software measures your face to fit glasses online.
privacy"Try On" Sunglasses Online? A Court Just Said Your Face Is Worth $5,000
A court just revived a lawsuit over a facial scan used to try on sunglasses online — and the reason why teaches something surprising about how biometric privacy law actually works. It's not about your face. It's about context.
biometricsYour Face, Their Loophole: Court Just Killed the "It's Healthcare" Excuse
You might think biometric privacy law is simple: did a company scan your face or not? A federal court ruling over virtual try-on glasses just proved that's only half the question. The other half is what changes everything.
