CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

Biometrics and Healthcare: Why Biometric Authentication Rarely Qualifies for BIPA's Exception

Your Face, Their Loophole: Court Just Killed the "It's Healthcare" Excuse
A face-scanning try-on tool illustrates the legal debate over biometrics and healthcare in Clements v. Gunnar Optiks.

Here's something that will mess with your head a little. Two businesses both scan your face. Both measure the exact same thing, the geometry of your features, the distances between your eyes, the curve of your jaw. One of them is doing it legally. The other is potentially on the hook for millions of dollars in fines. The face data is identical. The technology is identical. The only difference? Why they're doing it, and where.

TL;DR

A federal court just ruled that having a health-related product doesn't automatically protect a company from biometric privacy law, because the law cares about where your face is scanned and who you are in that moment, not just what the product does.

This isn't a hypothetical. A real case, Clements v. Gunnar Optiksjust made it through the 7th Circuit Court of Appeals (a major federal appeals court covering Illinois, Indiana, and Wisconsin), and it's one of those rulings that sounds boring until you realize it rewrites what you thought you knew about face data and privacy.

The Glasses That Opened a Legal Can of Worms

Gunnar Optiks sells eyewear. They built a virtual try-on tool, the kind where you upload a photo or use your camera, and the app places frames on your face so you can see how you'd look. Fun feature. Extremely useful. Also, as the lawsuit alleged, a potential violation of Illinois's Biometric Information Privacy Act, known as BIPA, the toughest biometric privacy law in the country.

BIPA, passed in 2008, requires companies to get your written consent before collecting biometric data, things like face geometry, fingerprints, voiceprints, or iris scans. The body stuff that's uniquely you and can't be changed if it leaks. It also requires companies to tell you why they're collecting it, how long they'll keep it, and whether they'll share it with anyone. Break those rules, and under BIPA, individual people can sue the company directly. Not just the government. You.

Gunnar's defense? Their product is eyewear. Eyewear has health applications. Therefore, they claimed, the facial scanning fell under BIPA's healthcare exception and they were exempt.

The court wasn't buying it.

427
BIPA class action lawsuits filed in a single year (2024)
Source: Biometric privacy litigation tracking, 2025

BIPA Healthcare Exception: The Two-Part Test

Here's where the law gets genuinely interesting. BIPA does have a healthcare exception. It's real. But it's not a blanket "health = exempt" pass. The law actually lays out two very specific situations where biometric data collection is protected from BIPA's requirements. This article is part of a series, start with Retail Facial Recognition Washington Privacy Gap.

Part One: The data was captured from a patient in a healthcare setting.

Part Two: The data was collected, used, or stored for healthcare treatment, payment, or operations, and it falls under HIPAA (the federal law that covers medical privacy, think doctor's offices, hospitals, insurance companies).

Both parts have to actually fit. And "fit" means something specific to courts, not just something that sounds reasonable in a press release.

Gunnar tried Part Two, arguing their face-scanning data was being collected for health-related purposes. But courts have been consistent on this: the question is not whether your product has a health connection. The question is whether the person being scanned is a patient, and whether the place they're being scanned is a healthcare setting. An online retail try-on tool is not a clinic. A person shopping for sunglasses is not a patient. The scan fails both tests even if the glasses technically sit on your face and protect your eyes from UV rays.

As Quarles Law noted in their analysis of the ruling, courts have specifically defined a "patient" as someone "presently awaiting or receiving care and treatment from a medical professional." Shopping for frames, even really nice frames, doesn't qualify.


Why Everyone Gets This Wrong (And It's Not Their Fault)

Most people hear "healthcare exception" and their brain fills in: health-related purpose = protected. That's intuitive. That's how a lot of everyday rules work. If your gym bag is for gym use, it goes in the gym locker room. If your data is for health use, it goes in the health exception. Simple category logic.

The law doesn't work that way. And honestly, the law is being deliberate about that. The people who wrote BIPA were worried about exactly this kind of reasoning, companies claiming a health angle to sidestep a privacy requirement that was designed to protect people from having their face data collected without their knowledge.

Think of it like food safety regulations. A restaurant can't just claim "we have a health purpose" to skip proper food-handling rules. The question is: what kind of establishment are you? A hospital pharmacy preparing medication under strict medical protocols gets different rules than a grocery store. A smoothie stand can claim health benefits all day long, still has to follow the same food safety code as every other food vendor. Same logic applies here. The product's health angle doesn't transform the setting or the relationship. Previously in this series: Its Healthcare Wont Save Your Face Scan Anymore.

"Whether a company can avoid Illinois's biometric information privacy law simply because its product has a health-related purpose is answered 'no, at least not without some evidence to support this assertion.'" 7th Circuit Court analysis, as reported by Law.com

That phrase, "at least not without some evidence", is the court basically saying: show your work. Don't just wave the health card. Prove you actually fit the legal definition, step by step.

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Same Face, Different BIPA Healthcare Rules

Let's make this concrete, because this is the part that should genuinely surprise you.

Imagine three scenarios. In all three, the exact same facial geometry measurement is happening, the system maps the distances between your eyes, the width of your nose, the proportions of your face.

Scenario A: An ophthalmologist (eye doctor) in a clinic scans your face to precisely fit prescription lenses. You are a patient. You are in a healthcare setting. The data goes toward HIPAA-covered treatment. BIPA's healthcare exception likely applies. The clinic probably doesn't need to go through BIPA's full consent process.

Scenario B: A retail website's virtual try-on tool scans your face so you can see how sunglasses look. You are a consumer. You are in a commercial setting. The data is used for a shopping feature. BIPA applies fully, written consent required, retention policy required, no selling the data without permission.

Scenario C: A telehealth platform scans your face to help a remote optometrist assess your needs. You might be a patient. The setting is digital. HIPAA might apply, or might not, depending on how the platform is structured. Legally murky, which is exactly why litigation in this space keeps growing.

Same technology. Three different legal outcomes. The scan doesn't change. The law's answer to "is this okay?" changes based entirely on context. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.

At CaraComp, we think about this distinction constantly, because when you work with face-based identity tools, the purpose of any given scan is never just a business decision. It's a legal one.

What You Just Learned

  • 🧠 BIPA is the strongest biometric privacy law in the U.S.It's the only one that lets you personally sue a company for mishandling your face data, not just regulators.
  • 🔬 The healthcare exception has two specific prongs"patient in a healthcare setting" AND "HIPAA-covered use." A health-adjacent product doesn't automatically satisfy either one.
  • ⚖️ Courts demand evidence, not vibesClaiming a health purpose without proving you fit the legal definition is exactly the kind of argument the 7th Circuit just rejected.
  • 💡 Context is the actual variableThe same face scan can be legally required, legally exempt, or legally uncertain depending on where it happens and who you are in that moment.

Why This BIPA Healthcare Exception Case Matters Broadly

BIPA has generated billions of dollars in settlements since 2008. Google settled an Illinois class action for $100 million over facial recognition data collected without clear consent. Over 100 new BIPA lawsuits were filed in 2025 alone, and that's actually down from 427 the year before, after a 2024 amendment limited how damages stack up for repeated violations against the same person.

But here's the thing about that amendment: it made the math smaller, not the liability itself. Companies still have to prove they complied. They still have to show consent was obtained, retention limits were set, and, critically, that any exemption they claim actually fits. The Gunnar ruling proves courts aren't just rubber-stamping healthcare claims. They're making companies show their work.

And face-scanning tools are everywhere now. Skincare apps. Fitness platforms. Insurance tools. Retail try-ons. Job interview software. Every single one of those involves some form of facial measurement, and every single one sits somewhere on that spectrum between "clearly covered by BIPA" and "claims to be exempt."

Key Takeaway

When any app or store wants to scan your face, the smart question isn't just "are they using face recognition?" It's three questions: Why are they collecting it? How long will they keep it? And under what rules are they operating? Those three answers tell you more about your actual privacy than the technology itself ever will.

The ACLU of Illinois has long argued that BIPA's power comes from exactly this specificity, the law forces companies to answer those questions in writing, before they scan you, not after. That disclosure requirement is what makes it different from most privacy laws, which only require companies to disclose after the fact in a privacy policy that no one reads.

So next time an app wants to map your face to "help you find the right frames" or "match your skin tone" or "personalize your experience", you now know the question to ask isn't just whether they're doing it. It's whether the reason they're doing it actually changes the rules they have to follow. And if they can't answer that clearly? That's your answer right there.

Biometrics and Healthcare: Where Patient Identification Actually Lives

The relationship between biometrics and healthcare is narrower than most people assume. A hospital using biometric authentication for patient identification at check-in is operating inside a healthcare setting, with a patient, for a healthcare purpose, that's the combination BIPA's exception was built for. A retail app measuring the same face geometry for a shopping feature has none of those three ingredients, which is exactly why the Gunnar court drew the line where it did.

Healthcare Biometrics: Security Without the Legal Shortcut

Healthcare biometrics still have to follow strict security and compliance rules even when BIPA's exception does apply. HIPAA requires hospitals and clinics to keep biometric identifiers secure, limit who on staff can access them, and maintain audit systems that track every use. Biometric security in a medical setting isn't a loophole around privacy law, it's a different privacy law, with its own compliance obligations around data management and information handling.

Biometric Authentication in Patient Identification Systems

Biometric authentication is increasingly used for patient identification because it reduces mix-ups between similarly named patients and speeds up check-in. A fingerprint or face scan tied to a medical record is more reliable than a birthdate lookup, especially in large hospital systems juggling thousands of patient records. But efficiency gains don't erase the underlying requirement that the system be secure, that staff be trained on proper handling, and that the biometric data be stored under the same protections as the rest of a patient's medical information.

Biometric Solutions Built for Actual Clinics, Not Retail Lookalikes

A genuine biometric solution for a hospital looks very different from a virtual try-on tool, even if both technically scan a face. The hospital version is built around patient identity verification, integrated with medical record systems, and governed by HIPAA-level compliance from day one. The retail version is built around convenience and conversion, which is precisely why it can't borrow the healthcare exception just because a health-adjacent product happens to sit nearby.

This distinction matters more as biometric technology spreads into new corners of healthcare. Biometric identifiers now show up in telehealth logins, pharmacy pickup verification, and insurance portals, not just hospital front desks. Each of those uses has to be checked against the same two-part test: is the person a patient, and is the setting a healthcare one governed by HIPAA. When both answers are yes, the healthcare exception can apply. When either answer is no, ordinary biometric privacy law, including BIPA's consent, retention, and disclosure rules, applies in full, regardless of how the marketing describes the product.

For companies building biometric authentication into patient identification workflows, the safest approach is to document the healthcare relationship clearly. That means recording who counts as a patient at the moment of the scan, confirming the setting qualifies as healthcare treatment, payment, or operations, and keeping the compliance paperwork ready in case a court asks for it later. The Gunnar ruling makes clear that courts will ask. Biometric security policies that assume the exception applies without checking both prongs are the same policies that end up defending a lawsuit instead of avoiding one. Patient trust in biometric systems depends on this discipline just as much as legal compliance does, patients who understand that their biometric data is protected by HIPAA-grade security tend to accept these systems more readily than patients facing an unexplained face scan at checkout.

Biometrics and healthcare intersect most visibly at the patient identification desk, but the deeper story is about how biometric data moves once it's collected. A biometric patient record isn't just a face scan or a fingerprint sitting in a file, it's biometric data that has to be linked correctly to the rest of a person's medical records, stored securely, and made available only to the staff who actually need it for treatment. Get that link wrong, and you don't just have a privacy problem, you have a patient safety problem, because the wrong biometric data attached to the wrong medical records can cause real procedure identification errors.

That's part of why hospitals invest so heavily in biometric authentication for patient identification rather than relying on names and birthdates alone. Two patients with the same name, born the same year, is a more common problem than people expect in a large hospital system, and mixing up their medical records can lead to the wrong medication, the wrong procedure, or a delayed diagnosis. Biometric data, a fingerprint, an iris scan, a face scan, ties a person to their own records in a way that's much harder to duplicate by accident. This is one of the clearest cases where biometrics and healthcare genuinely improve patient safety rather than just adding convenience.

Still, biometric authentication only helps if the underlying security holds up. A hospital that collects biometric data for patient identification but stores it carelessly hasn't actually solved the mix-up problem, it's just added a new kind of sensitive information to protect. Biometric security in a clinical setting means encrypting the biometric data at rest, limiting which systems can query it, and logging every time someone pulls a patient's biometric record. Those security habits matter as much as the accuracy of the fingerprint or face scan itself.

Recognition technology is the piece that actually does the matching, comparing a new fingerprint or face scan against what's stored to confirm a patient's identity. Good recognition systems are tuned to reduce false matches, which matters enormously in a hospital where a false match could mean pulling up the wrong patient's medical records. This is a different engineering problem than the retail recognition tools used for virtual try-ons, even though both technologies start with the same basic biometric capture step.

It improves convenience for patients too, not just for hospital staff managing records. A returning patient who can confirm their identity with a fingerprint or face scan doesn't have to dig through a wallet for an insurance card or repeat their birthdate at three different desks. But convenience is a side benefit of a system that has to be built around security and consent first, not the justification for skipping those requirements, which is exactly the mistake Gunnar made when it tried to lean on a health-adjacent product to sidestep BIPA.

Healthcare providers looking to reduce patient identification errors should treat biometric authentication as one layer in a broader information security program, not a standalone fix. That means training staff on how biometric data is captured and stored, auditing which systems have access to it, and making sure any vendor providing the biometric technology can demonstrate HIPAA-grade security practices. Healthcare support for these systems also needs to address how patients are informed, most healthcare support mfa requirements now expect some form of documented notice before biometric data is collected, mirroring the consent principle BIPA applies outside the exception.

None of this means biometric technology is risky by nature. It means the healthcare context changes what "doing it right" requires. A clinic using biometric authentication for patient identification, with proper security, proper consent documentation, and proper integration into medical records systems, is doing exactly what BIPA's healthcare exception anticipated. A retail app borrowing the language of health without any of that underlying structure is doing something else entirely, and the Gunnar ruling is the clearest reminder yet that courts can tell the difference.

Frequently asked questions

Does biometric face scanning for health products count as biometrics and healthcare data under BIPA?

Not automatically. A federal appeals court ruled that having a health-related product does not shield a company from Illinois's biometric privacy law. Biometrics and healthcare only overlap under BIPA's exception when the person is an actual patient being scanned in an actual healthcare setting, not simply because the item being sold, like eyewear, has health applications.

What is the two-part test for the BIPA healthcare exception?

The exception requires that the data was captured from a patient in a healthcare setting, and that the data was collected, used, or stored for treatment, payment, or operations covered by HIPAA. Both parts must actually fit; a court found that a retail try-on tool scanning a shopper's face does not meet either part, even though eyewear has a health connection.

Why do companies mistakenly think biometrics and healthcare products are exempt from privacy law?

People assume a health-related purpose automatically triggers protection, similar to simple category logic. But courts look at who the person is and where the scan happens, not just what the product does. A shopper trying on sunglasses online isn't a patient in a healthcare setting, so the biometrics and healthcare exception doesn't apply despite the product's health angle.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search