CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

Biometric Privacy Laws: Court Rejects BIPA Health Exemption

"It's Healthcare" Won't Save Your Face Scan Anymore

An eyewear company got sued for scanning customers' faces. Its defense? "We sell prescription glasses. That's healthcare. Healthcare gets a pass." A federal appeals court looked at that argument and basically said: nice try.

TL;DR

Just because a company calls its product "health-related" does NOT automatically mean your face scan is protected by healthcare privacy rules, and a recent federal court ruling makes that clearer than ever.

This matters to you even if you've never heard of the Illinois law at the center of this case. Because the same assumption that tripped up this company, "health context = automatic privacy exemption", is one that millions of regular people make too. And it's wrong in a way that could leave your most personal data completely exposed.

First, What Even Is a Biometric Scan?

Quick definition so we're on the same page: biometric data is any measurement taken from your body that can identify you, your face shape, your fingerprints, the pattern of your iris (the colored part of your eye), even the way you walk. Unlike a password, you can't change these. If a company loses your password, you reset it. If a company loses your facial geometry, that's yours forever, and so is whoever gets ahold of it.

Illinois recognized this back in 2008 and passed a law called BIPA, the Biometric Information Privacy Act. It requires companies to tell you before they collect your biometric data, explain why they're collecting it, say how long they'll keep it, and get your written permission. Simple enough in theory. The problem is what happens when a company thinks it doesn't have to follow those rules.

Illinois Biometric Information Privacy Act (BIPA) Basics

The Illinois Biometric Information Privacy Act, known as BIPA, is the oldest and most tested of the state biometric privacy laws in the country. It sets the baseline that other biometric privacy laws borrow from: written notice before collection, a stated purpose, a disclosed retention schedule, and consent that the person actually gave, not consent buried in fine print. Understanding BIPA helps you understand every other biometric privacy law you'll run into, because most states copied its structure.

BIPA Healthcare Exception: Why Eyewear's Argument Failed

Gunnar Optiks, a company that makes specialty eyewear, built a virtual try-on feature. You load it up, it scans your face, and you can see what their glasses would look like on you. Convenient! Also, according to a class action lawsuit, potentially a BIPA violation, because customers weren't properly told their facial geometry was being captured and stored.

Gunnar's defense leaned hard on the idea that eyewear, especially prescription eyewear, is health-adjacent enough to qualify for BIPA's healthcare exemption. The Seventh Circuit Court of Appeals (a federal appeals court covering Illinois, Indiana, and Wisconsin) disagreed. As DiCello Levitt reported in their analysis of the ruling, the appellate court found that whether the exemption even applied was a question requiring real evidence, not something a company could just assert and walk away from. This article is part of a series, start with Retail Facial Recognition Washington Privacy Gap.

The court revived the class action. Meaning: the case moves forward, and Gunnar has to actually prove its claim, not just label itself as health-related and expect the lawsuit to disappear.

"Companies should not treat the exemption as a broad safe harbor for health-adjacent technologies." Analysis from Quarles Law Firm, on the 7th Circuit's Gunnar Optiks ruling

Washington Biometric Law Compared to Illinois BIPA

Illinois isn't the only place with biometric privacy laws on the books, and the Washington biometric law works a little differently. Washington's biometric law generally requires notice and consent before biometric identifiers get collected for a commercial purpose, but it does not include the same private right to sue that makes BIPA so powerful. That difference matters a lot in practice: under Washington biometric law, enforcement mostly runs through the state attorney general rather than individual lawsuits, while Illinois lets regular people bring their own claims.

How Courts Apply the Two-Prong Test to BIPA Claims

Here's where this gets genuinely interesting, and where most people's assumptions fall apart. BIPA's healthcare exemption isn't one big fuzzy rule that says "healthcare = exempt." It actually has two very specific pathways, and a company has to qualify for one of them.

Pathway one is about location. The exemption covers biometric data "captured from a patient in a healthcare setting", but only if the person is presently awaiting or receiving medical care at the time. Notice how specific that is. Not "near a healthcare product." Not "about to maybe need an eye exam someday." Actually in the middle of receiving care, right now.

Pathway two is about purpose. It covers biometric data used for specific functions defined under HIPAA, that's the federal healthcare privacy law, like treatment, payment processing, or healthcare operations. Again, very specific. Not "our product relates to eyes." The actual purpose of collecting the data has to connect to one of those defined HIPAA functions.

Shopping online for glasses fails both tests. You're not receiving medical care when you're sitting on your couch at 10pm browsing eyewear. And scanning your face to show you what frames look like isn't a HIPAA-defined treatment or operational function. The Illinois First District Appellate Court made this same point in an earlier, related case: an online retail environment is simply not a healthcare setting, full stop.

$100M+
Illinois BIPA class action settlements have reached into the hundreds of millions for tech companies and employers
Because damages are awarded per violation, one lawsuit can be enormous

Consent Requirements Under State Biometric Laws

Consent is the word that does the heaviest lifting across every biometric privacy law, and it's worth being precise about what real consent looks like. Under BIPA and similar state biometric laws, consent means the company told you, in writing, before collecting your biometric information, what it was collecting, why, and how long it would keep it, and then you agreed. Consent buried inside a fifteen-page terms-of-service document that nobody reads does not meet that bar in the way courts are now interpreting these laws, which is exactly why the private entity in this case is having to defend its practices in front of a judge instead of just pointing to its checkout page.

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Why People Get This Wrong (And It's Not Their Fault)

Here's the thing: the reason people assume "healthcare" means "exempt from privacy rules" is actually pretty logical. The healthcare industry did successfully push for exemptions to reduce compliance friction, doctors and hospitals collect biometric data constantly, and requiring written consent for every blood pressure reading or fingerprint scan would be genuinely chaotic. So the exemptions exist for good reason. Previously in this series: Your Kids App Says Verified Heres Why Thats A Lie.

The problem is that businesses and consumers both took a shortcut. They heard "healthcare gets a pass" and interpreted it as "anything health-flavored gets a pass." That leap feels reasonable! If your doctor's office can scan your face without extra paperwork, why not a company selling you prescription glasses?

Because, as the courts are now making very clear, "health-flavored" and "healthcare" are not the same thing. The label on the product doesn't matter. The actual purpose of the data collection does. Think of it this way: claiming a healthcare exemption for any biometric scan because the product touches health is like claiming medical necessity to skip informed consent on a procedure just because it takes place inside a hospital building. The building doesn't grant the permission. The specific, documented purpose does.

As McGuireWoods noted in their analysis of the Illinois Supreme Court's interpretation of BIPA, the healthcare exemption applies narrowly to specific HIPAA-defined purposes, and courts now evaluate this with real scrutiny, not a rubber stamp.


What This Means the Next Time Someone Scans Your Face

At CaraComp, we spend a lot of time thinking about what facial recognition technology actually does under the hood, how face scans are captured, stored, and matched. And one thing that comes up constantly is how rarely people know what questions to ask before they hand over their biometric data. This ruling gives you a framework.

When any business, an eyewear store, a gym, a pharmacy kiosk, an app, wants to scan your face or eyes, "it's for your health" is not a complete answer. The questions that actually matter are:

Why, specifically, are you collecting this? Not the product category. The actual purpose of this specific scan, right now. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.

Are you telling me in writing before you collect it? BIPA requires written notice. If you're just clicking "accept" on a vague terms page, that's worth pausing on.

How long will you keep it? BIPA requires companies to disclose their retention timeline. "Until it's no longer needed" is not an answer.

These aren't trick questions. A company with a legitimate use case can answer them clearly. If the answer is fumbling or vague, that's information too.

What You Just Learned

  • 🧠 The healthcare exemption has two prongslocation-based (are you actively receiving care?) and purpose-based (is this a HIPAA-defined function?). Both are narrow.
  • 🔬 Courts now demand proof, not labelsa company can't just call itself health-related and skip biometric privacy rules. It has to show evidence that the exemption actually fits.
  • ⚖️ Notice, purpose, and consent still applyeven in genuinely health-adjacent contexts, the burden is on the company to show why each specific data collection qualifies for an exemption.
  • 💡 You have the right to ask"why are you collecting this, and how long will you keep it?" are questions any legitimate biometric data collector should be able to answer clearly.
Key Takeaway

When a company scans your face and calls it "health-related," that phrase does not automatically grant them an exemption from biometric privacy rules. What matters is the specific purpose of the scan and whether they gave you proper written notice before collecting anything, not what industry they're in.

The Gunnar Optiks ruling sends a message companies are going to have to hear: the exemption requires proof, not assumptions. But here's the version that's useful to you specifically, if a store, app, or clinic ever asks for a face or eye scan, the right response isn't "I guess that's fine, it's health stuff." The right response is curiosity. Ask what it's for. Ask what gets stored. Ask how long they keep it.

The companies that can answer those questions clearly probably have nothing to hide. The ones that fumble? Well. Now you know what questions to ask next.

Zooming out, this ruling is really about how biometric privacy laws get enforced in practice, not just how they're written. A law on paper only matters if courts hold companies to its actual text instead of letting them wave a general "healthcare" label at a judge. That's the real significance of the Gunnar Optiks decision for anyone tracking biometric privacy laws across the country.

It's worth remembering that biometric information privacy act cases like this one tend to move slowly. A revived class action doesn't mean a verdict tomorrow, it means the company now has to produce evidence, sit through discovery, and possibly go to trial or settle. For the individual whose face was scanned, that process can take years, even when the underlying facts seem straightforward.

Security is a word that comes up constantly around biometric data, and it's worth separating from privacy, even though the two overlap. Privacy law like BIPA governs whether a company was allowed to collect your data and whether it told you first. Security is a separate question: once that data exists in a company's servers, how well is it protected from hackers, leaks, or misuse? BIPA touches security indirectly by requiring reasonable protection standards, but the consent and notice requirements are really about privacy first.

This is also why biometric information keeps showing up in class actions rather than regulatory fines alone. Because BIPA lets private individuals sue directly, plaintiffs' attorneys have a strong incentive to bring these cases, and biometric information collected without proper notice becomes the central piece of evidence. That private right of action is a big reason Illinois biometric information privacy act cases move faster and settle bigger than claims under states without a similar provision.

If you're trying to figure out whether a particular company obtained your consent properly, look for three things: a standalone notice (not buried in a general privacy policy), a clear statement of purpose, and a retention schedule. If a business can't produce all three, it likely didn't obtain valid consent under BIPA, no matter what it claims about being health-related.

The broader lesson for anyone following biometric privacy laws is that labels don't do legal work. A company doesn't get to declare itself exempt; it has to prove, with evidence, that its specific conduct fits inside a narrow legal definition. That single idea, proof over labels, is likely to shape how courts handle biometric privacy laws for years to come.

Frequently asked questions

What are biometric privacy laws and why do they matter?

Biometric privacy laws govern how companies collect data like facial geometry, fingerprints, or iris patterns that can identify you. Illinois's BIPA, passed in 2008, is the oldest and most tested of these laws, requiring written notice, a stated purpose, a disclosed retention schedule, and real consent before collection. Unlike a password, biometric data can't be changed once it's exposed, which is why these laws treat it so seriously.

Does a healthcare exemption apply under biometric privacy laws?

Not automatically. BIPA's healthcare exemption only applies through two narrow pathways: data captured from a patient actually receiving care in a healthcare setting, or data used for HIPAA-defined functions like treatment or payment processing. A federal appeals court rejected an eyewear company's claim that selling prescription glasses made its face-scanning try-on feature exempt, since browsing online isn't receiving medical care.

What counts as valid consent under biometric privacy laws?

Under BIPA and similar biometric privacy laws, valid consent means a company gave written notice before collecting biometric data, explaining what it collected, why, and how long it would be kept, followed by actual agreement. Consent hidden inside a lengthy terms-of-service document that nobody reads doesn't meet that standard under how courts are currently interpreting these requirements.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search