CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

Medical Biometrics: Court's BIPA Ruling Redraws the Line

That "Virtual Try-On" for Glasses? A Court Just Ruled It's Scanning Your Face — Not Your Health
A shopper's face is scanned for a virtual eyewear try-on, raising legal questions about medical biometrics and consent.

Picture this: you're shopping for glasses online, you click "try on virtually," your camera flips on, and your face gets mapped in seconds. It feels fun, a little futuristic. You pick your frames, check out, and move on. You almost certainly did not think: wait, what just happened to a scan of my face?

TL;DR

A federal appeals court just ruled that virtual eyewear try-on tools are not healthcare — meaning companies can't use a "healthcare exemption" to skip the strict consent rules that protect your biometric data (your face scan, your eye map, your body's unique markers), and courts are making that loophole narrower every year.

A federal court just weighed in on exactly that question — and the answer has real consequences for anyone who's ever tried on glasses, contacts, or eyewear through an app or website. The 7th Circuit Court of Appeals (one step below the Supreme Court, covering Illinois, Indiana, and Wisconsin) revived a class-action lawsuit against an eyewear company, ruling that its virtual try-on feature is "aesthetic, not medical." The company had argued it should be exempt from Illinois' strict biometric privacy law because, hey, glasses are kind of healthcare-adjacent, right? The court's response, more or less: nice try.

Biometric Camera Laws: BIPA's Healthcare Loophole

Illinois has a law called BIPA — the Biometric Information Privacy Act. Think of it as a bill of rights for your body data. Biometric data just means the physical stuff that's uniquely you: your face geometry, your iris pattern, your fingerprints, the way you walk. This is different from a password. You can change a password. You cannot change your face.

BIPA says that if a company wants to collect that data from Illinois residents, it has to tell you first, get your written agreement, and follow strict rules about how long it keeps that data and who it shares it with. No sneaking. No vague terms buried on page 12 of a privacy policy that nobody reads.

The law has teeth. Since roughly 2018, more than 2,000 lawsuits have been filed under BIPA — not just against tech giants, but against employers, retailers, and yes, eyewear companies. The cases are accelerating, not slowing down.

2,000+
BIPA lawsuits filed since roughly 2018, spanning employers, retailers, and consumer apps — not just big tech
Source: WilmerHale 2024 BIPA Litigation Review

There is, however, a carve-out — an exemption — for healthcare. The logic makes sense on its face: if you're at a doctor's office and they're scanning your eye to check for glaucoma, that's a medical situation governed by a whole other set of federal privacy rules (called HIPAA — basically the law that keeps your doctor from posting your medical records on the internet). BIPA essentially says: if HIPAA already covers you, you don't have to comply with us too. This article is part of a series — start with Your Face Was Scanned Saturday Nobody Asked If That Was Lega.

Some companies looked at that exemption and saw a golden ticket.

Facial Recognition Virtual Try-Ons Lose Healthcare Status

The company at the center of this ruling — Gunnar Optiks, known for blue-light-blocking glasses — offered a virtual try-on feature. Customers could use their camera to see how different frames would look on their face. The company argued this was healthcare-related enough to qualify for BIPA's exemption.

The 7th Circuit disagreed, bluntly.

"Better-appearing glasses are not medical treatment." — 7th Circuit Court of Appeals, as reported by Law.com

That one sentence does a lot of work. It draws a clean line between actual medical eye care — where a licensed professional examines your eyes, makes a clinical judgment, and documents it in your medical record — and a shopping tool that lets you preview frames. One is medicine. One is retail with a cool camera trick.

The court also noted something that matters even more for the future: to legitimately claim the healthcare exemption, a company would need to actually comply with HIPAA — the federal healthcare privacy law. You can't just wave your hand and say "we're healthcare" to dodge BIPA. You'd have to walk the walk: formal privacy notices, protected health records, real accountability to the Department of Health and Human Services. Most retail tech companies haven't done any of that. They just liked the sound of "exempt."


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Why Biometric Camera Risks Go Beyond Eyewear

Here's where it gets interesting — and a little uncomfortable. Virtual try-on tools aren't limited to eyewear anymore. Makeup brands, hair color apps, hat retailers, plastic surgery preview tools, hearing aid fitters — dozens of consumer categories now use your face as a fitting room. The same legal question applies to all of them: does the word "health" in the product description automatically protect the company from biometric privacy rules? Based on this ruling, no. Previously in this series: Your Bosss Ai Can Reject You Until 2027 And Nobody Has To Pr.

Legal analysts at Freeman Mathis & Gary noted that even at the Illinois state court level, a prior decision had already drawn this same boundary: the healthcare exclusion under BIPA applies only where "trained and licensed professionals collect biometric identifiers from individuals seeking out medical care." Not an app. Not a website checkout flow. An actual clinical setting with actual licensed professionals.

The trend is clear. Courts are getting more specific, not less. The exemption is narrowing. And any company that planned to rely on being "health-adjacent" to avoid consent requirements is now on notice.

Why This Ruling Matters — Even If You Don't Live in Illinois

  • It sets a pattern — Federal rulings influence how other states and courts think about biometric privacy, even where BIPA doesn't directly apply. Illinois leads; others follow.
  • 📊 It touches normal errands — Virtual try-on, face-based authentication, optical fitting tools — these aren't exotic tech. They're showing up in ordinary shopping and healthcare-adjacent services everywhere.
  • 🔍 It puts the responsibility back on companies — Claiming a healthcare exemption now requires proving real HIPAA compliance, not just using healthcare-sounding language in a privacy policy.
  • 🔮 It previews the next fight — As more consumer products scan faces "for fit" or "for health," the question of what counts as legitimate healthcare data collection is only going to get louder.

What You Can Actually Do Right Now

Look, nobody expects you to read a 14-page privacy policy before trying on virtual glasses at midnight. But there are three questions worth asking — out loud, or in a quick search — any time an app or website wants access to your face or eyes for something that isn't a doctor's appointment:

Is this data being stored, or is it only processed in the moment? Some tools genuinely process your face locally and never send it anywhere. Others save it to a server. The difference is enormous. If a company can't tell you clearly, that's your answer.

Can this data be shared or sold? Biometric data — your face map, your iris geometry — is valuable. It can train AI systems. It can be licensed. It can end up in places you never imagined when you clicked "try it on." A company serious about privacy will tell you explicitly that your biometric data is never sold or shared with third parties.

Does "healthcare" actually mean anything here? If a company is implying its use of your face data is medical or clinically meaningful, ask who the licensed professionals are and whether the service is covered by federal healthcare privacy law. If the answer is vague, the "healthcare" framing is probably marketing, not legal protection. Up next: Monroe County Biometric Disclosure Retail Facial Recognition.

If you've ever wondered whether a face scan is actually what it claims to be — just a fitting tool, or something more — that's the exact question this kind of law exists to force companies to answer out loud. National Law Review's analysis of BIPA litigation trends makes clear that courts are now expecting those answers to be specific, documented, and given in advance — not buried in terms of service after the scan already happened.

Key Takeaway

"Healthcare-adjacent" is not a legal shield. If a company wants to scan your face — for glasses, for a fitness app, for anything — it either has to get your real, informed consent or prove it's a fully HIPAA-compliant medical provider. Courts are now enforcing that distinction. You should too.

The counterargument is worth acknowledging, briefly: some legal commentators worry that making the healthcare exemption too narrow will scare legitimate eyecare innovators away from useful tools — virtual fitting that reduces returns, improves prescription accuracy, helps people with limited mobility shop from home. Those are real benefits. Nobody's saying face-scanning technology is inherently bad. The question is just: if you want my face data, tell me the truth about what you're doing with it. That should not be a hard ask.


The WilmerHale review of 2024 BIPA litigation describes a clear pattern: courts are moving toward narrower exemptions, higher consent standards, and more scrutiny of companies that claim special status without actually meeting the requirements for it. That trend didn't slow down in 2025. This ruling suggests it's not slowing down in 2026 either.

So the next time a glasses website asks to see your face — and promises it's totally fine because they're in the eyecare business — remember that a federal court just told a glasses company, in writing, that wanting you to look good in frames is not the same thing as medicine. Your face data doesn't stop being yours just because someone is selling you something you put near your eyes.

It helps to understand what a biometric camera actually does before you decide whether to trust one. A biometric camera is not a normal camera that just takes a picture and stores it as a photo file. Instead, the camera module inside these systems captures dozens or hundreds of specific measurements — the distance between your eyes, the curve of your cheekbones, the shape of your jaw — and turns those measurements into a mathematical map. That map, not a picture, is usually what gets stored and analyzed.

This is the core difference between a biometric camera and facial recognition software running somewhere else on a photo you already uploaded. A biometric camera is doing the capture and the analysis at the same moment, often on specialized cameras optimized for depth sensing rather than color detail. That is why a virtual try-on feature can spin your glasses around in 3D as you turn your head — the camera is tracking a live, moving biometric recognition map, not a flat photo.

Facial detection and facial recognition are related but not identical. Facial detection is the simpler job: the camera just figures out "yes, there is a face in this frame" so it can point the try-on graphics in the right place. Facial recognition camera systems go a step further and try to identify or verify who that face belongs to, or build a unique biometric technology profile of it for later use. Most virtual try-on tools only need facial detection to work, which is one reason critics ask why so many of them collect and keep more biometric data than the actual task requires.

Iris scanning is a separate category worth knowing about, since it often gets lumped in with facial biometric tools in casual conversation. Iris scanning reads the unique pattern in the colored part of your eye, which is even more specific to you than general face geometry. Some vision and eyewear apps have experimented with iris scanning for prescription accuracy, and that is exactly the kind of feature that raises the healthcare-exemption question this article covers — is an iris scan for frame-fitting a medical act, or just a very precise measurement tool?

Identity authentication is another use case that gets confused with simple try-on convenience. Identity authentication uses a biometric camera to confirm you are who you say you are — unlocking a phone, approving a payment, or logging into an account. That is a different purpose than fitting glasses, and it usually comes with its own separate consent screen. If a virtual try-on app quietly reuses your face capture for identity authentication later, that reuse itself may need fresh consent under laws like BIPA.

None of this makes biometric camera technology inherently untrustworthy. A camera that captures your face geometry to show how sunglasses look on you is doing something useful and, when handled honestly, fairly low-risk. The legal risk shows up when a company blurs the line between that limited capture and a broader biometric recognition system it never clearly disclosed. Knowing the difference between simple facial detection, deeper facial recognition, and true biometric authentication gives you the vocabulary to ask sharper questions before you let any camera map your face.

When you are deciding whether to let an app use its camera this way, it helps to ask exactly what kind of capture is happening. Ask whether the biometric recognition data is deleted right after the session, or stored for future use across other products. Ask whether the specialized cameras optimized for this task are also capable of full facial recognition, even if the current feature only uses facial detection. A company that can answer these questions clearly, in plain language, is generally more trustworthy than one that just repeats the word "biometric technology" without explaining what it means for your specific face data.

Biometric Systems in Everyday Healthcare Settings

Biometric systems are showing up well beyond eyewear apps, and hospitals are one of the biggest adopters. A hospital biometric system might scan a patient's palm or iris at check-in so the front desk can pull up the right chart instantly, cutting down on mixed-up records between two patients with similar names. These biometric systems work differently from a retail try-on tool because they usually operate under HIPAA, which means the patient data collected has to meet a much stricter bar for consent, storage, and sharing than a glasses website ever would.

The distinction matters because not every biometric system that touches a healthcare provider automatically counts as medical use. A biometric patient identification platform used to confirm someone's identity before surgery is doing genuine clinical work. A biometric system bolted onto a hospital gift shop checkout, by contrast, is closer to the retail scenario the 7th Circuit just rejected — and healthcare providers who blur that line could face the same BIPA exposure as any eyewear brand.

Biometric Authentication for Patient Identity

Biometric authentication in a clinical setting usually exists to solve one specific problem: making sure the person receiving care, medication, or a procedure is actually the patient named on the chart. Patient identity mix-ups are a real safety issue, and biometric authentication — a fingerprint, a face scan, an iris read — can confirm patient identity faster and more reliably than asking someone to spell their name at a busy front desk.

But biometric authentication used for patient identity still has to be built and disclosed correctly. A hospital that authorizes access to patient records based on a fingerprint scan needs the same kind of clear, upfront consent that BIPA already demands elsewhere, even though HIPAA also applies. Biometric authentication that quietly expands from "confirm this is the right patient" to "build a permanent biometric profile shared across other healthcare providers" is exactly the kind of scope-creep this ruling warns about.

How Healthcare Providers Use Biometric Technology Today

Healthcare providers have adopted biometric technology for more than just front-desk check-in. Some hospitals use biometric data to authorize access to medication dispensing cabinets, so only the assigned nurse can open a specific drawer. Others use biometric systems to secure entry to sensitive areas like a records room or a neonatal unit, where knowing exactly who came and went matters for both security and patient safety.

These uses of biometric technology tend to sit more comfortably inside HIPAA's protections than a retail face scan does, precisely because a licensed healthcare provider is collecting the data as part of delivering or securing care. Still, the same basic test the 7th Circuit applied to eyewear applies here too: is the biometric data collection tied to an actual clinical or safety purpose, or is it a convenience feature dressed up in healthcare language to avoid stricter consent rules?

Privacy and Security Tradeoffs in Biometric Data

Privacy is the concern that follows biometric data everywhere it goes, whether the setting is a hospital or a shopping app. Because biometric identifiers like a fingerprint or face map can never be reset the way a password can, any security failure involving biometric data is permanent in a way that a leaked password simply is not. That is one reason regulators treat biometric authentication and biometric systems in healthcare with extra caution, even when HIPAA already applies.

Security for biometric data in a healthcare setting generally means limiting who can access the raw biometric data, encrypting it both in storage and in transit, and keeping a clear record of every time that data is used to authorize access. Privacy protections layer on top of that security by requiring patients to actually understand, in advance, what their biometric data will be used for and who else might see it. A healthcare provider that can explain both its security safeguards and its privacy commitments in plain language is doing the part of this work that the Gunnar Optiks ruling shows so many retail companies skipped.

Remote and Mobile Biometric Patient Identification

Remote care has pushed biometric patient identification beyond the hospital lobby and into phones and tablets. A mobile app that lets a patient check in for a telehealth visit might ask for a quick face scan or fingerprint to confirm patient identity before connecting the call, which helps prevent someone else from using a patient's login to get a prescription refill under the wrong name.

Remote and mobile biometric identification tools raise the same disclosure questions as any other biometric system: is the data processed only in the moment and discarded, or stored for future use across other digital health products from the same company? Staff building these remote tools should be able to answer that question as clearly as any hospital records department can, because a digital front door to healthcare still has to meet the same consent bar as the physical one.

Ultimately, the same test applies whether the biometric solutions in question sit in a hospital, a telehealth app, or an eyewear website: does the biometric data collection serve a genuine medical or safety purpose carried out by accountable professionals, or is it a shortcut dressed in healthcare language to avoid consent? Biometrics in healthcare can be a real safety upgrade when it is disclosed honestly and secured properly. Biometrics used as a marketing label to dodge privacy law, as this ruling shows, does not hold up in court.

Where Body Measurements Fit Into Patient Identification

Body measurements are part of what makes biometric patient identification reliable, since features like hand geometry, iris patterns, and fingerprint ridges rarely change once adulthood is reached. A hospital that captures these body measurements for patient identification is relying on the same basic idea as a fingerprint lock on a phone: the measurement is stable enough to trust every single time someone checks in. That stability is exactly why regulators hold body measurements collected for patient identification to a higher security standard than an ordinary photo.

Not every body measurement needs to become part of a permanent biometric record, though. A nurse jotting down height and weight for a chart is not doing biometric patient identification in the legal sense; the concern kicks in specifically when body measurements are converted into a unique biological template used to confirm identity going forward. Healthcare providers that keep this distinction clear tend to have an easier time explaining their biometrics program to patients and regulators alike.

Areas of Care Where Biometrics Are Used Most

Certain areas of a hospital or clinic system rely on biometrics more heavily than others. Surgical suites, medication dispensing areas, newborn nurseries, and records departments are common areas where biometric authentication does real safety work, because the cost of a mix-up in those areas is high. Emergency departments are another one of these areas, since patients arriving unconscious or unable to speak still need to be matched correctly to their medical history.

Outside those higher-stakes areas, biometrics show up in lower-risk spots too, like staff time clocks or building entry points. The 7th Circuit's reasoning suggests that courts will keep looking closely at exactly which areas of a healthcare business actually justify the healthcare exemption, rather than accepting that any use of biometrics anywhere on a medical campus automatically qualifies.

Patient identification errors are one of the clearest reasons healthcare biometrics exist in the first place, and fingerprint identification remains one of the most common tools for solving that problem at check-in and medication administration. A well-run patient identification program pairs fingerprint identification or another biometric screening step with a human double-check, so a single bad scan cannot cause a mix-up on its own. Healthcare biometrics significantly reduce medical identity fraud when they are layered this way, rather than relied on as the only safeguard.

Clinical screening performed with a biometric step still needs a documented, disclosed reason behind it, the same way any other patient identification tool does. Unique biological markers like an iris pattern or fingerprint ridge pattern make biometric screening extremely accurate, but accuracy alone does not satisfy consent law; a hospital still has to tell patients, in plain terms, that biometrics are used and why. That combination of accuracy and honest disclosure is what keeps a genuine healthcare biometrics program on the right side of the line the 7th Circuit just drew for eyewear companies.

Frequently asked questions

What is medical biometrics and how does it relate to virtual try-on tools?

Medical biometrics refers to physical data like face geometry, iris patterns, and fingerprints collected in genuine clinical settings by trained, licensed professionals treating patients. Virtual try-on tools, like eyewear apps that scan your face for fit, are not medical biometrics even if the product is health-adjacent, because a court ruled that such scans are aesthetic, not medical treatment.

Can companies claim a healthcare exemption to avoid biometric privacy laws?

Not simply by calling their product health-related. The 7th Circuit ruled that a virtual eyewear try-on feature does not qualify for BIPA's healthcare exemption, stating that better-appearing glasses are not medical treatment. To legitimately claim the exemption, a company must actually comply with HIPAA, including formal privacy notices and protected health records, not just healthcare-sounding language.

Does BIPA's healthcare exemption apply to makeup, hair, or hearing aid apps that scan your face?

Based on this ruling, no. The healthcare exclusion applies only where trained and licensed professionals collect biometric identifiers from individuals seeking medical care, not through an app or website checkout flow. Makeup brands, hair color apps, hat retailers, and hearing aid fitters using facial scans face the same legal question as eyewear companies, and courts are narrowing the exemption rather than expanding it.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search