Is GIPA the Next BIPA? What Illinois Employers Need to Know
GIPA, the Illinois Genetic Information Privacy Act, is not a new version of BIPA. It’s a separate, older law. It regulates genetic information instead of biometric data. But it’s riding the same wave of Illinois plaintiff’s-bar lawsuits. And its per-violation penalties are higher than BIPA’s.
GIPA is formally known as 410 ILCS 513. Illinois lawmakers passed it in 1998. They expanded it in 2008 to align in part with the federal Genetic Information Nondiscrimination Act (GINA). The law borrows its definition of genetic information from HIPAA. It also separately reaches direct-to-consumer commercial genetic testing companies.
So if you’ve been tracking BIPA litigation risk and now see GIPA lawsuits in the news, you’re right to ask whether this is the same problem again. It isn’t the same law. But it can hit the same HR intake process, and the numbers are bigger.
GIPA vs. BIPA: How the Two Laws Differ
The two laws get confused constantly, and it’s easy to see why. Both are Illinois-only privacy statutes. Both let an individual sue directly, without a regulator involved. Both have become magnets for class-action litigation. Here’s where they actually split:
| GIPA | BIPA | |
|---|---|---|
| Full name | Illinois Genetic Information Privacy Act | Illinois Biometric Information Privacy Act |
| Statute | 410 ILCS 513 | 740 ILCS 14 |
| What it regulates | Genetic testing and genetic information | Fingerprints, face/hand geometry, retina/iris scans, voiceprints |
| First enacted | 1998 (expanded 2008) | 2008 |
| Lets an individual sue directly | Yes | Yes |
GIPA is actually the older of the two laws by a decade. BIPA gets more press because of its huge biometric settlements. Fingerprint time clocks are common workplace equipment. GIPA cases are quieter but growing fast, and they hide inside a form most HR teams treat as routine: the pre-employment health questionnaire.
Who GIPA Applies To
GIPA reaches further than most employers assume. It isn’t limited to labs or genetic testing companies. It covers anyone who touches an employee’s or applicant’s genetic information in the ordinary course of doing business, including:
- Employers, including the State of Illinois, local governments, and private companies
- Employment agencies and labor organizations
- Licensing agencies
- Insurers and managed care plans regulated by the Illinois Department of Insurance
- Health care providers and health facilities
That first category is the one that surprises most business owners. You don’t have to run a lab or handle DNA samples to fall under GIPA. Asking the wrong question on an intake form is enough.
The Employer Trap Driving the 2023-2024 Lawsuit Surge
Here’s where most of the recent GIPA lawsuits start. GIPA bars employers from soliciting, requesting, requiring, or purchasing genetic testing or genetic information about an employee or applicant. It also bars using that information as a condition of employment.
That sounds like it only applies to actual lab tests. It doesn’t.
A routine pre-employment physical can trigger it. So can a standard health questionnaire. If either one asks about family medical history, that question alone can count as soliciting genetic information under GIPA. No blood draw or lab result needs to be involved.
Think about how many occupational health intake forms ask something like “does anyone in your immediate family have a history of heart disease, diabetes, or cancer?” That’s a completely standard question on countless employment physicals. Under GIPA, it’s also the exact fact pattern driving the current lawsuit wave.
Legal trackers reported more than 50 GIPA class actions filed in 2023 alone. Most followed this same pattern: an employer’s pre-employment physical or health questionnaire asked about family medical history. A smaller group involved life insurers whose underwriting process asked similar questions during applications.
The trap is that the form looks completely normal. It probably came from a clinic’s standard intake packet, not from HR. Nobody drafted it with GIPA in mind. That gap between how routine the question feels and what the statute actually prohibits is exactly what’s fueling the current surge in filings.
GIPA’s Confidentiality Rule and Written Authorization
GIPA treats genetic information as confidential and privileged. An employer or other covered entity can’t share it freely, even internally.
The law only allows release to the person tested, or to someone that person authorizes in writing. Narrow exceptions exist: certain criminal investigations, treatment and payment operations, and public health activities.
Verbal consent isn’t enough. A written authorization has to exist before any genetic information changes hands.
That standard matters for HR departments handling employee files. A manager can’t just ask a nurse practitioner for a family history summary over the phone. The written-authorization requirement applies every time, not just at intake.
GIPA vs. BIPA: Comparing the Penalties
GIPA’s liquidated damages run higher than BIPA’s on both tiers. Here’s the side-by-side comparison:
| GIPA (410 ILCS 513) | BIPA (740 ILCS 14) | |
|---|---|---|
| Negligent violation | $2,500 or actual damages, whichever is greater | $1,000 or actual damages, whichever is greater |
| Intentional/reckless violation | $15,000 or actual damages, whichever is greater | $5,000 or actual damages, whichever is greater |
| Attorney’s fees | Recoverable by prevailing plaintiff | Recoverable by prevailing plaintiff |
| Private right of action | Yes | Yes |
GIPA’s damages are two and a half times BIPA’s on the negligent tier. They’re three times higher on the intentional tier. Plaintiffs can also recover expert witness fees under GIPA, along with attorney’s fees and costs.
Why the Lawsuit Surge Happened Now
Three things lined up to make GIPA attractive to plaintiff’s attorneys:
- Fee-shifting. A prevailing plaintiff recovers attorney’s fees and costs, so firms can take GIPA cases on contingency without much financial risk.
- Higher damages than BIPA. The $2,500/$15,000 range beats BIPA’s $1,000/$5,000, making each case worth more to file.
- A form that’s easy to find. Pre-employment physicals and health questionnaires asking about family medical history are common and easy to spot in discovery.
Put those three together and GIPA looks, to a plaintiff’s firm, like BIPA’s higher-paying cousin. The underlying conduct, a boilerplate health form, is often unintentional. That doesn’t reduce the exposure.
What This Means for Your HR Intake and IT Systems
Two separate teams need to look at this, not just legal.

HR side: Every pre-employment physical, health questionnaire, and wellness-program intake form needs a review. Strip any question asking about family medical history, unless a specific, GIPA-compliant exception applies. This is a legal drafting question. LeadingIT doesn’t write consent language or HR forms. An employment attorney should review the actual wording.
IT and data-handling side: This is where LeadingIT’s work sits. Health questionnaire responses often end up stored digitally, in an HRIS, a shared drive, or an email inbox. That data needs the same access controls and confidentiality treatment GIPA requires on paper.
The same logic applies to the biometric side of Illinois privacy law. See our BIPA compliance guide for employers if you also use fingerprint or facial-recognition time clocks. Our guide on biometric time clocks covers the same kind of exposure.
Both laws share one theme. Whatever system holds the sensitive data needs documented access limits, not just a signed form on file.
See Where You Stand
LeadingIT doesn’t have a dedicated GIPA self-check yet. The free 2-minute BIPA Risk-Check covers the same Illinois employee-data exposure questions many employers are also asking about genetic privacy. Start there to see where your intake and data-handling gaps sit.
Take the free 2-minute BIPA Risk-Check
Related Guides
Frequently Asked Questions
No, they’re two separate Illinois statutes. GIPA covers genetic information and testing, and dates back to 1998. BIPA covers biometric identifiers like fingerprints and facial scans, and dates to 2008. Both give individuals the right to sue directly, but their penalty amounts differ.
GIPA applies to employers, including the State of Illinois, local governments, and private companies. It also covers employment agencies, labor organizations, licensing agencies, insurers and managed care plans, and health care providers and facilities.
Not under GIPA. Employers may not solicit, request, require, or purchase genetic testing or genetic information from an employee or applicant. A question about family medical history on a physical or health questionnaire can count as soliciting genetic information, even without a lab test.
A negligent violation carries liquidated damages of $2,500 or actual damages, whichever is greater. An intentional or reckless violation carries $15,000 or actual damages, whichever is greater. Prevailing plaintiffs can also recover attorney’s fees, costs, and expert witness fees.
No. Biometric time clocks fall under BIPA, which regulates fingerprints, facial geometry, and similar identifiers. GIPA covers genetic information and testing instead, a separate category of data. An employer could face exposure under both laws if it handles both kinds of data carelessly.
No. LeadingIT is a managed IT and cybersecurity provider, not a law firm. It helps secure the systems and vendor relationships that store sensitive data, and helps produce documentation your attorney needs. Drafting consent language or HR forms is an employment attorney’s job.
Get Your Intake Process and Data Handling Reviewed
GIPA exposure usually starts in a form nobody thought to check. It ends up touching whatever system stores the response. LeadingIT helps Illinois employers secure that side: access controls, vendor review, and the documentation your attorney needs to close the gap.
See LeadingIT’s IT compliance services for Illinois businesses, or book a call to talk through your setup. You can also contact us directly, or call 815-788-6041.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
