CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

"It's Healthcare" Won't Save Your Face Scan Anymore

"It's Healthcare" Won't Save Your Face Scan Anymore

An eyewear company got sued for scanning customers' faces. Its defense? "We sell prescription glasses. That's healthcare. Healthcare gets a pass." A federal appeals court looked at that argument and basically said: nice try.

TL;DR

Just because a company calls its product "health-related" does NOT automatically mean your face scan is protected by healthcare privacy rules — and a recent federal court ruling makes that clearer than ever.

This matters to you even if you've never heard of the Illinois law at the center of this case. Because the same assumption that tripped up this company — "health context = automatic privacy exemption" — is one that millions of regular people make too. And it's wrong in a way that could leave your most personal data completely exposed.

First, What Even Is a Biometric Scan?

Quick definition so we're on the same page: biometric data is any measurement taken from your body that can identify you — your face shape, your fingerprints, the pattern of your iris (the colored part of your eye), even the way you walk. Unlike a password, you can't change these. If a company loses your password, you reset it. If a company loses your facial geometry, that's yours forever — and so is whoever gets ahold of it.

Illinois recognized this back in 2008 and passed a law called BIPA — the Biometric Information Privacy Act. It requires companies to tell you before they collect your biometric data, explain why they're collecting it, say how long they'll keep it, and get your written permission. Simple enough in theory. The problem is what happens when a company thinks it doesn't have to follow those rules.

The Eyewear Company's Argument — And Why It Failed

Gunnar Optiks, a company that makes specialty eyewear, built a virtual try-on feature. You load it up, it scans your face, and you can see what their glasses would look like on you. Convenient! Also, according to a class action lawsuit, potentially a BIPA violation, because customers weren't properly told their facial geometry was being captured and stored.

Gunnar's defense leaned hard on the idea that eyewear — especially prescription eyewear — is health-adjacent enough to qualify for BIPA's healthcare exemption. The Seventh Circuit Court of Appeals (a federal appeals court covering Illinois, Indiana, and Wisconsin) disagreed. As DiCello Levitt reported in their analysis of the ruling, the appellate court found that whether the exemption even applied was a question requiring real evidence — not something a company could just assert and walk away from. This article is part of a series — start with Retail Facial Recognition Washington Privacy Gap.

The court revived the class action. Meaning: the case moves forward, and Gunnar has to actually prove its claim, not just label itself as health-related and expect the lawsuit to disappear.

"Companies should not treat the exemption as a broad safe harbor for health-adjacent technologies." — Analysis from Quarles Law Firm, on the 7th Circuit's Gunnar Optiks ruling
Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Court-ready facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

The Two-Prong Test Nobody Tells You About

Here's where this gets genuinely interesting — and where most people's assumptions fall apart. BIPA's healthcare exemption isn't one big fuzzy rule that says "healthcare = exempt." It actually has two very specific pathways, and a company has to qualify for one of them.

Pathway one is about location. The exemption covers biometric data "captured from a patient in a healthcare setting" — but only if the person is presently awaiting or receiving medical care at the time. Notice how specific that is. Not "near a healthcare product." Not "about to maybe need an eye exam someday." Actually in the middle of receiving care, right now.

Pathway two is about purpose. It covers biometric data used for specific functions defined under HIPAA — that's the federal healthcare privacy law — like treatment, payment processing, or healthcare operations. Again, very specific. Not "our product relates to eyes." The actual purpose of collecting the data has to connect to one of those defined HIPAA functions.

Shopping online for glasses fails both tests. You're not receiving medical care when you're sitting on your couch at 10pm browsing eyewear. And scanning your face to show you what frames look like isn't a HIPAA-defined treatment or operational function. The Illinois First District Appellate Court made this same point in an earlier, related case: an online retail environment is simply not a healthcare setting, full stop.

$100M+
Illinois BIPA class action settlements have reached into the hundreds of millions for tech companies and employers
Because damages are awarded per violation — one lawsuit can be enormous

Why People Get This Wrong (And It's Not Their Fault)

Here's the thing: the reason people assume "healthcare" means "exempt from privacy rules" is actually pretty logical. The healthcare industry did successfully push for exemptions to reduce compliance friction — doctors and hospitals collect biometric data constantly, and requiring written consent for every blood pressure reading or fingerprint scan would be genuinely chaotic. So the exemptions exist for good reason. Previously in this series: Your Kids App Says Verified Heres Why Thats A Lie.

The problem is that businesses and consumers both took a shortcut. They heard "healthcare gets a pass" and interpreted it as "anything health-flavored gets a pass." That leap feels reasonable! If your doctor's office can scan your face without extra paperwork, why not a company selling you prescription glasses?

Because, as the courts are now making very clear, "health-flavored" and "healthcare" are not the same thing. The label on the product doesn't matter. The actual purpose of the data collection does. Think of it this way: claiming a healthcare exemption for any biometric scan because the product touches health is like claiming medical necessity to skip informed consent on a procedure just because it takes place inside a hospital building. The building doesn't grant the permission. The specific, documented purpose does.

As McGuireWoods noted in their analysis of the Illinois Supreme Court's interpretation of BIPA, the healthcare exemption applies narrowly to specific HIPAA-defined purposes — and courts now evaluate this with real scrutiny, not a rubber stamp.


What This Means the Next Time Someone Scans Your Face

At CaraComp, we spend a lot of time thinking about what facial recognition technology actually does under the hood — how face scans are captured, stored, and matched. And one thing that comes up constantly is how rarely people know what questions to ask before they hand over their biometric data. This ruling gives you a framework.

When any business — an eyewear store, a gym, a pharmacy kiosk, an app — wants to scan your face or eyes, "it's for your health" is not a complete answer. The questions that actually matter are:

Why, specifically, are you collecting this? Not the product category. The actual purpose of this specific scan, right now. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.

Are you telling me in writing before you collect it? BIPA requires written notice. If you're just clicking "accept" on a vague terms page, that's worth pausing on.

How long will you keep it? BIPA requires companies to disclose their retention timeline. "Until it's no longer needed" is not an answer.

These aren't trick questions. A company with a legitimate use case can answer them clearly. If the answer is fumbling or vague, that's information too.

What You Just Learned

  • 🧠 The healthcare exemption has two prongs — location-based (are you actively receiving care?) and purpose-based (is this a HIPAA-defined function?). Both are narrow.
  • 🔬 Courts now demand proof, not labels — a company can't just call itself health-related and skip biometric privacy rules. It has to show evidence that the exemption actually fits.
  • ⚖️ Notice, purpose, and consent still apply — even in genuinely health-adjacent contexts, the burden is on the company to show why each specific data collection qualifies for an exemption.
  • 💡 You have the right to ask — "why are you collecting this, and how long will you keep it?" are questions any legitimate biometric data collector should be able to answer clearly.
Key Takeaway

When a company scans your face and calls it "health-related," that phrase does not automatically grant them an exemption from biometric privacy rules. What matters is the specific purpose of the scan and whether they gave you proper written notice before collecting anything — not what industry they're in.

The Gunnar Optiks ruling sends a message companies are going to have to hear: the exemption requires proof, not assumptions. But here's the version that's useful to you specifically — if a store, app, or clinic ever asks for a face or eye scan, the right response isn't "I guess that's fine, it's health stuff." The right response is curiosity. Ask what it's for. Ask what gets stored. Ask how long they keep it.

The companies that can answer those questions clearly probably have nothing to hide. The ones that fumble? Well. Now you know what questions to ask next.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search