Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

BIPA for Illinois Healthcare Employers: What the HIPAA Exemption Does and Doesn’t Cover

August 11, 2026
hero-bipa-for-illinois-healthcare-employers-1.png

Illinois’ Biometric Information Privacy Act (BIPA) carves out a real, HIPAA-linked exemption for healthcare employers. Many hospital, clinic, and long-term-care administrators assume it covers more than it actually does. It does not exempt every fingerprint scanner or badge reader just because the employer handles protected health information.

The Illinois Supreme Court narrowed and clarified this exemption in 2023. The ruling helps. It also leaves real gaps unresolved, especially for general employee time clocks.

This page draws the line as precisely as current case law allows. It covers what the statute actually excludes, what the Illinois Supreme Court has and hasn’t decided, and where a healthcare employer still needs a written opinion from an employment attorney before assuming a biometric system is exempt.

The Statutory Carve-Out: What BIPA Actually Excludes

BIPA’s definition of “biometric identifier” contains a built-in healthcare exclusion. Two categories of information fall outside the law entirely under 740 ILCS 14/10:

  • Information captured from a patient in a health care setting
  • Information collected, used, or stored for health care treatment, payment, or operations under HIPAA
How BIPA's Carve-Out Works

Both exclusions trace back to HIPAA’s own framework. “Treatment, payment, or operations” is a defined concept under HIPAA that covers the routine business of running a health care practice, not just direct patient care. BIPA borrows that concept rather than defining its own separate standard.

BIPA Healthcare Data Exclusions

Read narrowly, this exclusion is straightforward for patient-facing biometric identification. A hospital that scans a patient’s fingerprint or iris to confirm identity during treatment isn’t collecting a “biometric identifier” under BIPA at all. That data sits outside the statute from the start.

The harder question is what happens when the person being scanned is not the patient, but the employee. Does a nurse’s own fingerprint, scanned to access a piece of medical equipment, get the same exclusion? For years, that question had no clear answer in Illinois case law.

Mosby v. Ingalls Memorial Hospital: The Exemption Can Reach Employees Too

The Illinois Supreme Court answered that question in [Mosby v. The facts were specific. Nurses at the hospital scanned their fingerprints to open medication-dispensing cabinets holding controlled substances. Those cabinets exist to control access to medication during patient treatment.

Employee Biometric Exemption Test

The Court held that this fingerprint data fell within BIPA’s HIPAA-linked exemption, even though the person scanned was an employee, not a patient. The key fact was purpose. The scans were tied directly to accessing medication for patient care, not to a general HR or payroll function.

This was a meaningful clarification. Before Mosby, some read the exemption as covering patient data only. The Court rejected that narrow reading. A health care worker’s own biometric data can be exempt, but only when it’s collected for a genuine treatment-related purpose.

That distinction, purpose over identity, is the whole holding. It’s not “healthcare workers are exempt.” It’s “this specific use, tied to this specific patient-care function, is exempt.”

What Mosby Doesn’t Settle: General Time Clocks Are an Open Question

Decision aid showing which biometric scanners fall under the BIPA healthcare exemption: medication cabinet access is exempt, patient identification scans fall outside BIPA, and general payroll time clocks are not automatically exempt.

The Illinois Supreme Court was explicit about the limits of its own ruling. Legal analysis from Jackson Lewis confirms the Court refused to treat Mosby as a blanket rule. It declined to exempt “all biometric identifiers taken from health care workers” simply because the employer is a hospital or clinic.

That refusal matters most for one specific, very common system: the general employee attendance time clock.

Comparison of three biometric use scenarios in Illinois healthcare settings and their BIPA exemption status: medication-cabinet access, attendance time clocks, and patient scans

Picture a hospital that uses a fingerprint scanner for staff to clock in and out. That system tracks payroll and scheduling. It has no connection to medication access, patient charts, or clinical equipment. Mosby did not squarely decide whether that kind of time clock qualifies for the HIPAA-linked exemption.

Here’s the practical distinction so far:

  • Fingerprint scan to access a medication-dispensing cabinet for patient care: exemption applies, per Mosby.
  • Fingerprint scan for a general payroll and attendance time clock: exemption status is open. No Illinois Supreme Court ruling squarely covers it.

This is a real gap, not a technicality. A healthcare employer that assumes its attendance system is automatically exempt because Mosby exists is reading the case too broadly. The Illinois Supreme Court said the opposite: purpose controls, and a payroll function is not a treatment function on its face.

Healthcare employers should treat this as an open legal question. It is not a settled fact. Before assuming any specific time clock, badge system, or access-control scanner qualifies for the exemption, get a written opinion from an employment attorney who can review that system’s actual purpose and data flow. General assumptions based on “we’re a hospital, so BIPA doesn’t apply to us” don’t hold up under Mosby’s own language.

Comparing the Three Scenarios

Not every biometric scan in a healthcare setting gets the same treatment under BIPA. The purpose behind the scan decides the outcome, not the industry.

Biometric UseExemption StatusWhy
Medication-dispensing or controlled-substance cabinet accessExemption likely appliesTied directly to patient treatment, per Mosby v. Ingalls Memorial Hospital
General attendance or payroll time clockOpen question, confirm with counselNot addressed by Mosby. No direct link to treatment, payment, or operations
Patient-facing biometric identificationExcluded from BIPA entirelyFalls under the “patient in a health care setting” language in 740 ILCS 14/10

For a full breakdown of how BIPA treats biometric time clocks generally, see Are Biometric Time Clocks Legal in Illinois?

GIPA Adds a Second Layer for Healthcare Employers

BIPA isn’t the only Illinois privacy statute a healthcare employer needs to track. The Illinois Genetic Information Privacy Act (GIPA) covers a different kind of data entirely, and it names healthcare providers directly.

It restricts how genetic testing and genetic information about Illinois residents can be collected, used, and disclosed. GIPA reaches employers, insurers, managed care plans, health care providers, and health facilities by name.

That last part matters for hospitals and clinics specifically. GIPA doesn’t just apply to employers in general. It explicitly lists health care providers and insurers as covered entities.

The biggest trap sits in routine HR intake. Employers can’t solicit, request, or require genetic testing or genetic information as a condition of employment. A pre-employment physical or health questionnaire that asks about family medical history can count as soliciting genetic information, even with no lab test involved. For a hospital or clinic running standard pre-employment physicals, that’s a direct and common exposure point.

This isn’t a theoretical risk. Most alleged an employer or insurer improperly solicited family medical history during intake or underwriting. Read the full comparison in Is GIPA the Next BIPA?, and for background on the treatment, payment, and operations concept BIPA’s exemption borrows from, see What Is HIPAA?

Key Takeaways

  • BIPA’s HIPAA-linked exemption is narrow. It covers patient data and treatment-tied employee biometric use, not every scanner in a hospital.
  • Mosby confirmed the exemption can reach employee biometric data, but only for a genuine treatment-related purpose like medication-cabinet access.
  • General attendance time clocks are not automatically exempt. That question remains open and needs individual legal review.
  • GIPA separately and explicitly covers healthcare providers, insurers, and managed care plans, with higher damages than BIPA.
  • Staffing agency involvement doesn’t shift BIPA liability. It follows whoever actually operates the biometric system.

The Staffing and Travel-Nurse Angle

Many hospitals and clinics lean on staffing agencies for nursing and clinical coverage. That staffing relationship raises its own BIPA question: who’s liable if the biometric system belongs to the facility, not the agency?

The Illinois Appellate Court addressed this directly in Salinas v. Surestaff, LLC. That case involved a food manufacturing facility, not a hospital. But the legal principle transfers directly to healthcare staffing arrangements.

The staffing agencies in Salinas enrolled workers in the facility’s fingerprint time clock. They didn’t operate the system themselves. The court rejected the idea that merely facilitating access creates liability. BIPA requires actually acquiring or controlling the data.

For a hospital using travel nurses or agency clinical staff, this means the biometric time clock or badge system liability typically falls on the facility that runs it. The staffing agency supplying the nurse isn’t automatically on the hook, and the facility isn’t automatically shielded either. Whoever operates and controls the system carries the compliance burden, including getting valid written notice and consent from every worker who scans in, staffing-agency or not.

What This Means in Practice

Don’t treat “we’re a hospital” as a BIPA exemption by itself. That shortcut is exactly what Mosby warned against.

Instead, map each biometric system your facility uses to its actual purpose:

  1. Identify every biometric collection point: medication cabinets, supply rooms, badge readers, attendance clocks.
  2. Ask what the data is actually used for, not just who’s being scanned.
  3. Sort each system into “tied to treatment, payment, or operations” or “HR and payroll function.”
  4. Flag anything in the second category, including general time clocks, for legal review before assuming it’s exempt.
  5. Confirm who operates and controls each system, especially if staffing agencies or subcontracted clinical staff are involved.

A badge reader on a medication room door and a badge reader on the staff entrance can look identical. Under BIPA, they may not be treated the same way at all. For the complete BIPA compliance picture beyond this exemption, see the Illinois BIPA compliance guide for employers

See Where You Stand

Not sure which of your facility’s biometric systems fall inside the exemption and which don’t? Answer 8 plain-English questions about your time clocks, badge readers, and medication-cabinet access, and see your exposure level plus the gaps worth flagging for your attorney.

Take the free 2-minute BIPA Risk-Check

Frequently Asked Questions

No. BIPA’s exemption is narrow and purpose-based. It covers patient data and employee biometric data collected for a genuine treatment, payment, or operations purpose, not every biometric system a healthcare employer runs.

Yes, biometric time clocks are legal to use. BIPA doesn’t ban the technology. It requires written notice, a signed release, a public retention policy, and reasonable security before a hospital or any employer can use one.

No. The Illinois Supreme Court was explicit that Mosby is not a blanket exemption for all healthcare-worker biometric identifiers. It applied to fingerprint scans used specifically to access medication-dispensing cabinets for patient care.

That question is open. Mosby did not squarely decide whether a general payroll and attendance time clock, unconnected to medication or supply access, qualifies for the HIPAA-linked exemption. Get a written opinion from an employment attorney before assuming it does.

Yes. GIPA explicitly covers health care providers, health facilities, insurers, and managed care plans. A common trap is a pre-employment physical or health questionnaire that asks about family medical history, which can count as soliciting genetic information.

Generally no, if the agency only enrolls workers in a system it doesn’t operate. Illinois courts have held that BIPA liability follows whoever actually controls the biometric system, typically the facility running it, not the staffing agency supplying the workers.

Map the system to its actual purpose. If it’s tied directly to patient treatment, like medication-cabinet access, the exemption likely applies. If it’s a general HR or payroll function, treat it as an open question and confirm with an employment attorney.

The Mosby exemption is a legal question, and only your attorney can tell you where your specific systems land. LeadingIT’s role is different: securing the technical environment around whatever biometric or access-control systems your facility runs.

That includes configuring time clock and badge systems, securing the vendor connection between the platform and your network, and producing the documentation your attorney needs for compliant consent paperwork. See LeadingIT’s Illinois compliance services for the done-for-you path, book a call to talk through your facility’s setup, or contact us with questions.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.