Most Illinois dental and healthcare practices have never heard of BIPA until a demand letter shows up. Then they discover that the fingerprint time clock they bought to stop buddy-punching, or the face-scan kiosk their check-in vendor turned on by default, has been collecting biometric data from every employee and patient for three years — with no written consent, no retention policy, and no idea which vendor is storing it.
This is not a marketing problem or a HIPAA problem. It is a technology procurement problem, and it is solvable in an afternoon if you catch it early. Below is what BIPA covers, where biometric data actually hides inside a practice software stack, and the checklist we run when we audit a practice in Chicago, the Illinois suburbs, or anywhere the law reaches.
This article is general information for practice owners making technology decisions. It is not legal advice. Run any specific exposure past a qualified Illinois attorney.
What BIPA actually covers
The Illinois Biometric Information Privacy Act (740 ILCS 14, the full statute text from the Illinois General Assembly) became law in 2008 and remains the strictest biometric privacy law in the United States. What makes it unusual is that it gives private individuals the right to sue directly — they do not need a regulator to act first, and they do not need to prove they were actually harmed.
BIPA covers biometric identifiers: fingerprints, retina and iris scans, voiceprints, and scans of hand or face geometry. It does not cover a photograph on its own, a written signature, or a physical description. The line that matters for practices is this: a photo of a patient is not a biometric identifier, but a face-geometry template generated from that photo is.
The four things the law requires before you collect
- Written notice that biometric data is being collected or stored, and what specific identifier is involved.
- The purpose and length of time the data will be collected, stored, and used — stated up front, before collection starts.
- A signed written release from the person. Since the 2024 amendment, an electronic signature counts.
- A publicly available written retention and destruction policy, with a schedule that destroys the data when the purpose is satisfied or within three years of the person’s last interaction, whichever comes first.
Three of those four are paperwork. The fourth — actually destroying data on schedule — is the one that depends entirely on whether your vendor supports it. That is why this is a technology decision, not an HR one.
Where biometric data hides in a practice tech stack
Practice owners almost never buy “a biometric system.” They buy a scheduling tool, a payroll add-on, or a phone system, and biometrics arrive as a feature nobody read about. Here is where we find it.
Employee-facing systems
- Fingerprint and palm time clocks. By a wide margin the most common source of real BIPA claims in Illinois. If your payroll provider shipped a wall unit with a finger reader, you are collecting biometric identifiers.
- Face-unlock on shared operatory workstations. Convenient for clinical staff, and a biometric template all the same.
- Badge and door systems that use fingerprint or hand geometry for the sterilization room, drug storage, or server closet.
- Voice authentication inside a VoIP or answering platform used to verify staff identity.
Patient-facing systems
- Self-service check-in kiosks with facial recognition for returning patients.
- Identity-verification features bundled into patient portals and intake apps, especially ones that match a selfie to a driver’s license photo.
- AI receptionists and voice agents that offer voiceprint matching to identify a returning caller. This is the newest exposure and the one most practices have not thought about — it is worth reviewing before you deploy any AI phone or automation solution.
- Imaging and smile-simulation tools that build a facial geometry map rather than simply storing a photograph.
The healthcare exemption is narrower than most practices assume
BIPA contains an exemption for information collected for health care treatment, payment, or operations under HIPAA. Practice owners often hear “we’re a healthcare provider, we’re exempt” and stop there. That reading is wrong in a way that matters.
The Illinois Supreme Court addressed the scope of that exemption in Mosby v. Ingalls Memorial Hospital in late 2023, and the practical takeaway is narrow: the exemption turns on whether the biometric data was collected in connection with health care, not on whether the organization collecting it happens to be a healthcare provider. A fingerprint scan used to unlock a medication dispensing cabinet during patient care sits differently than a fingerprint scan used to clock in for a shift. Your status as a dental or medical practice does not blanket-exempt your payroll hardware.
The safe posture for a practice: assume employee timekeeping biometrics are covered, and get the consent paperwork right rather than betting on an exemption argument.
What changed in 2024, and why it does not mean you can relax
In 2023, the Illinois Supreme Court held in Cothron v. White Castle that every individual scan could count as a separate violation. For a practice with 20 employees clocking in twice a day, the arithmetic became absurd very quickly.
Illinois amended the statute in August 2024 to fix that. Repeated collection of the same biometric identifier from the same person by the same party now counts as a single violation, and electronic signatures were confirmed as valid written releases. Courts have continued to work through whether the amendment applies to conduct that predates it.
What did not change: statutory damages are still $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorney’s fees, and a plaintiff still does not need to show actual harm. A single violation per employee across a 30-person dental group is still a six-figure conversation. The 2024 amendment took the catastrophic scenario off the table. It did not take the expensive one off the table.
The 2026 BIPA technology checklist for Illinois practices
This is the sequence we work through during a technology audit. Most practices get through it in a single afternoon.
- Inventory every device and app that can read a person. Walk the building. Time clocks, kiosks, door readers, workstation logins, imaging software, the phone system. Write down the vendor for each.
- Ask each vendor one written question: “Does this product create, store, or transmit a biometric identifier or biometric template, and where is it stored?” Get the answer in writing. A template stored on the device is a different risk profile than one synced to a vendor cloud.
- Turn off what you do not need. This is the highest-leverage step and the one practices skip. If a PIN or badge does the job, disable the biometric option. Most time clocks support a non-biometric mode that nobody ever switched on.
- Collect written releases for what remains. Notice, purpose, duration, signature. Electronic signature is fine. New hires sign during onboarding; existing staff sign now, not at the next review cycle.
- Publish a retention and destruction schedule where it is publicly available, and confirm your vendor can actually execute deletion on that schedule. Ask them to show you the deletion function, not describe it.
- Check your vendor contracts for disclosure terms. BIPA restricts sharing biometric data with third parties without consent. If your time clock vendor uses a downstream processor, that is a disclosure.
- Store the releases where you can find them. Signed consents scattered across email are functionally the same as no consents. Keep them in your HR system or central practice CRM with the rest of your documentation.
- Apply the same security standard you use for PHI. Biometric data must be protected using the reasonable standard of care for your industry — which, for a practice, means the safeguards you already owe under the HHS HIPAA Security Rule.
If you are outside Illinois
Texas and Washington have biometric statutes, but neither gives individuals a private right to sue — enforcement runs through the state attorney general. Colorado, and a growing list of states with comprehensive privacy laws, now treat biometric data as sensitive data requiring opt-in consent. Several cities have their own rules.
Two practical notes for multi-state groups. First, if you operate in Illinois at all — even one location in the Chicago suburbs inside a group spread across the United States — BIPA reaches those employees and patients. Second, building your consent workflow to the Illinois standard everywhere is usually cheaper than maintaining different workflows per state, because Illinois is the ceiling.
We run this review as part of a broader technology audit for dental practices, chiropractic offices, and healthcare practices across Illinois and nationwide — usually alongside the vendor consolidation and integration work that surfaces these systems in the first place.
Frequently asked questions
Does BIPA apply to dental practices?
Yes. BIPA applies to any private entity operating in Illinois, including dental, chiropractic, and medical practices. The statute’s healthcare exemption covers biometric information collected in connection with health care treatment, payment, or operations — it does not exempt a practice’s employee timekeeping or building access systems.
Are fingerprint time clocks legal in Illinois?
They are legal, but only with compliance. Before the first scan you need written notice of what is being collected and why, a stated retention period, a signed written release from each employee, and a publicly available destruction policy. Biometric time clocks are the single most common source of BIPA claims in Illinois, so if you cannot produce those four items, switch to PIN or badge entry until you can.
What are the penalties for a BIPA violation?
Statutory damages are $1,000 for each negligent violation and $5,000 for each intentional or reckless violation, plus attorney’s fees and costs. Since the August 2024 amendment, repeated collection of the same biometric identifier from the same person counts as one violation rather than one per scan. Plaintiffs do not need to prove actual injury to recover.
Does HIPAA compliance cover BIPA?
No. They are separate laws with separate requirements. HIPAA governs protected health information and is enforced by federal regulators. BIPA governs biometric identifiers, applies to employees as well as patients, and is enforced primarily through private lawsuits. A practice can be fully HIPAA compliant and still have significant BIPA exposure through its time clock.
Do AI receptionists and voice agents create BIPA risk?
Only if they generate a voiceprint. An AI receptionist that transcribes speech and books appointments is not collecting a biometric identifier. One that builds a voice template to recognize a returning caller is. Ask the vendor in writing which of the two their product does before you deploy it.
Get a read on your own stack
If you cannot answer “which of our systems collects biometric data, and where is it stored” in under five minutes, that is the finding. It is also a fast one to fix — and it usually surfaces a handful of other things worth cleaning up at the same time.
Discover Solutions works as the fractional CTO for dental, chiropractic, and healthcare practices in Chicago, across Illinois, and throughout the United States. Book a free audit and we will inventory your stack, flag the biometric exposure, and hand you the checklist above filled in.
