CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

Your Face, Their Loophole: Court Just Killed the "It's Healthcare" Excuse

Your Face, Their Loophole: Court Just Killed the "It's Healthcare" Excuse

Here's something that will mess with your head a little. Two businesses both scan your face. Both measure the exact same thing — the geometry of your features, the distances between your eyes, the curve of your jaw. One of them is doing it legally. The other is potentially on the hook for millions of dollars in fines. The face data is identical. The technology is identical. The only difference? Why they're doing it, and where.

TL;DR

A federal court just ruled that having a health-related product doesn't automatically protect a company from biometric privacy law — because the law cares about where your face is scanned and who you are in that moment, not just what the product does.

This isn't a hypothetical. A real case — Clements v. Gunnar Optiks — just made it through the 7th Circuit Court of Appeals (a major federal appeals court covering Illinois, Indiana, and Wisconsin), and it's one of those rulings that sounds boring until you realize it rewrites what you thought you knew about face data and privacy.

The Glasses That Opened a Legal Can of Worms

Gunnar Optiks sells eyewear. They built a virtual try-on tool — the kind where you upload a photo or use your camera, and the app places frames on your face so you can see how you'd look. Fun feature. Extremely useful. Also, as the lawsuit alleged, a potential violation of Illinois's Biometric Information Privacy Act, known as BIPA — the toughest biometric privacy law in the country.

BIPA, passed in 2008, requires companies to get your written consent before collecting biometric data — things like face geometry, fingerprints, voiceprints, or iris scans. The body stuff that's uniquely you and can't be changed if it leaks. It also requires companies to tell you why they're collecting it, how long they'll keep it, and whether they'll share it with anyone. Break those rules, and under BIPA, individual people can sue the company directly. Not just the government. You.

Gunnar's defense? Their product is eyewear. Eyewear has health applications. Therefore, they claimed, the facial scanning fell under BIPA's healthcare exception and they were exempt.

The court wasn't buying it.

427
BIPA class action lawsuits filed in a single year (2024)
Source: Biometric privacy litigation tracking, 2025

The Two-Part Test Nobody Told You About

Here's where the law gets genuinely interesting. BIPA does have a healthcare exception. It's real. But it's not a blanket "health = exempt" pass. The law actually lays out two very specific situations where biometric data collection is protected from BIPA's requirements. This article is part of a series — start with Retail Facial Recognition Washington Privacy Gap.

Part One: The data was captured from a patient in a healthcare setting.

Part Two: The data was collected, used, or stored for healthcare treatment, payment, or operations — and it falls under HIPAA (the federal law that covers medical privacy — think doctor's offices, hospitals, insurance companies).

Both parts have to actually fit. And "fit" means something specific to courts, not just something that sounds reasonable in a press release.

Gunnar tried Part Two — arguing their face-scanning data was being collected for health-related purposes. But courts have been consistent on this: the question is not whether your product has a health connection. The question is whether the person being scanned is a patient, and whether the place they're being scanned is a healthcare setting. An online retail try-on tool is not a clinic. A person shopping for sunglasses is not a patient. The scan fails both tests even if the glasses technically sit on your face and protect your eyes from UV rays.

As Quarles Law noted in their analysis of the ruling, courts have specifically defined a "patient" as someone "presently awaiting or receiving care and treatment from a medical professional." Shopping for frames — even really nice frames — doesn't qualify.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Court-ready facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Why Everyone Gets This Wrong (And It's Not Their Fault)

Most people hear "healthcare exception" and their brain fills in: health-related purpose = protected. That's intuitive. That's how a lot of everyday rules work. If your gym bag is for gym use, it goes in the gym locker room. If your data is for health use, it goes in the health exception. Simple category logic.

The law doesn't work that way. And honestly, the law is being deliberate about that. The people who wrote BIPA were worried about exactly this kind of reasoning — companies claiming a health angle to sidestep a privacy requirement that was designed to protect people from having their face data collected without their knowledge.

Think of it like food safety regulations. A restaurant can't just claim "we have a health purpose" to skip proper food-handling rules. The question is: what kind of establishment are you? A hospital pharmacy preparing medication under strict medical protocols gets different rules than a grocery store. A smoothie stand can claim health benefits all day long — still has to follow the same food safety code as every other food vendor. Same logic applies here. The product's health angle doesn't transform the setting or the relationship. Previously in this series: Its Healthcare Wont Save Your Face Scan Anymore.

"Whether a company can avoid Illinois's biometric information privacy law simply because its product has a health-related purpose is answered 'no — at least not without some evidence to support this assertion.'" — 7th Circuit Court analysis, as reported by Law.com

That phrase — "at least not without some evidence" — is the court basically saying: show your work. Don't just wave the health card. Prove you actually fit the legal definition, step by step.

Same Face. Completely Different Rules.

Let's make this concrete, because this is the part that should genuinely surprise you.

Imagine three scenarios. In all three, the exact same facial geometry measurement is happening — the system maps the distances between your eyes, the width of your nose, the proportions of your face.

Scenario A: An ophthalmologist (eye doctor) in a clinic scans your face to precisely fit prescription lenses. You are a patient. You are in a healthcare setting. The data goes toward HIPAA-covered treatment. BIPA's healthcare exception likely applies. The clinic probably doesn't need to go through BIPA's full consent process.

Scenario B: A retail website's virtual try-on tool scans your face so you can see how sunglasses look. You are a consumer. You are in a commercial setting. The data is used for a shopping feature. BIPA applies fully — written consent required, retention policy required, no selling the data without permission.

Scenario C: A telehealth platform scans your face to help a remote optometrist assess your needs. You might be a patient. The setting is digital. HIPAA might apply, or might not, depending on how the platform is structured. Legally murky — which is exactly why litigation in this space keeps growing.

Same technology. Three different legal outcomes. The scan doesn't change. The law's answer to "is this okay?" changes based entirely on context. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.

At CaraComp, we think about this distinction constantly — because when you work with face-based identity tools, the purpose of any given scan is never just a business decision. It's a legal one.

What You Just Learned

  • 🧠 BIPA is the strongest biometric privacy law in the U.S. — It's the only one that lets you personally sue a company for mishandling your face data, not just regulators.
  • 🔬 The healthcare exception has two specific prongs — "patient in a healthcare setting" AND "HIPAA-covered use." A health-adjacent product doesn't automatically satisfy either one.
  • ⚖️ Courts demand evidence, not vibes — Claiming a health purpose without proving you fit the legal definition is exactly the kind of argument the 7th Circuit just rejected.
  • 💡 Context is the actual variable — The same face scan can be legally required, legally exempt, or legally uncertain depending on where it happens and who you are in that moment.

Why This Matters Beyond One Eyewear Company

BIPA has generated billions of dollars in settlements since 2008. Google settled an Illinois class action for $100 million over facial recognition data collected without clear consent. Over 100 new BIPA lawsuits were filed in 2025 alone — and that's actually down from 427 the year before, after a 2024 amendment limited how damages stack up for repeated violations against the same person.

But here's the thing about that amendment: it made the math smaller, not the liability itself. Companies still have to prove they complied. They still have to show consent was obtained, retention limits were set, and — critically — that any exemption they claim actually fits. The Gunnar ruling proves courts aren't just rubber-stamping healthcare claims. They're making companies show their work.

And face-scanning tools are everywhere now. Skincare apps. Fitness platforms. Insurance tools. Retail try-ons. Job interview software. Every single one of those involves some form of facial measurement, and every single one sits somewhere on that spectrum between "clearly covered by BIPA" and "claims to be exempt."

Key Takeaway

When any app or store wants to scan your face, the smart question isn't just "are they using face recognition?" It's three questions: Why are they collecting it? How long will they keep it? And under what rules are they operating? Those three answers tell you more about your actual privacy than the technology itself ever will.

The ACLU of Illinois has long argued that BIPA's power comes from exactly this specificity — the law forces companies to answer those questions in writing, before they scan you, not after. That disclosure requirement is what makes it different from most privacy laws, which only require companies to disclose after the fact in a privacy policy that no one reads.

So next time an app wants to map your face to "help you find the right frames" or "match your skin tone" or "personalize your experience" — you now know the question to ask isn't just whether they're doing it. It's whether the reason they're doing it actually changes the rules they have to follow. And if they can't answer that clearly? That's your answer right there.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search