BIPA and the Pharmacy Counter: Face Match, Fingerprints, and Prescription Pickup
Showing a driver's license to collect a prescription is being replaced by a camera that recognizes you, a reader that takes your print, or a phone line that verifies your voice. Every one of those is a biometric identifier under Illinois law, and the most common defense — "we're a health care provider, HIPAA covers this" — is far narrower than pharmacy operators assume.
Four places a pharmacy collects biometrics
Operators usually think about one deployment and miss the other three. Each is a separate collection with its own notice, release, and retention obligation:
Patient identity at the counter or drive-thru
Face match against an enrollment photo, or a fingerprint tied to the patient profile, replacing the ID check at dispensing. This is the deployment with the strongest treatment-and-operations argument — and the one most likely to be undermined by a second purpose bolted onto the same camera.
Controlled substance and safe access
Biometric locks on the CII safe and on the dispensing workstation. The subject here is an employee, so no patient exclusion is available, and the DEA's security expectations do not create a BIPA safe harbor. Regulatory necessity is not consent.
Time and attendance
The classic BIPA fact pattern, now common in pharmacy back rooms and warehouse fulfillment. Purely an employment collection with no health care angle whatsoever.
Voice verification on refill and IVR lines
Voiceprints are enumerated biometric identifiers under BIPA. A refill line that enrolls a caller's voice to skip authentication questions is collecting one, and the enrollment prompt almost never contains a written release.
The health care exclusion, read correctly
BIPA carves out information collected, used, or stored for treatment, payment, or health care operations under HIPAA, and it carves out patient information in a health care setting. Pharmacy counsel tends to read that as "pharmacies are exempt." The better reading, and the one litigation has borne out, is that the exclusion follows the purpose of the specific collection.
Two consequences follow, and both cut against the operator:
- Employee collections are outside it entirely. A pharmacist's fingerprint is not patient information. Courts have consistently refused to extend the health care exclusion to staff biometrics at hospitals and pharmacies, and this is where the reliable defense verdicts are absent.
- A second purpose contaminates the first. The moment the pickup camera also feeds loss prevention, footfall analytics, an ad-measurement pixel, or a shrink model, the collection is no longer solely for treatment, payment, or operations. Pharmacies frequently install one system and then let a retail team attach a second use to it, without anyone re-running the legal analysis.
What compliance looks like in practice
BIPA is unusual among privacy statutes in that its core requirements are concrete and checkable. A compliant deployment has all of the following, in writing, before enrollment:
- A publicly available written policy setting a retention schedule and destruction guidelines. The statutory outer bound is the earlier of the purpose being satisfied or three years after the individual's last interaction. "We keep it as long as needed" is not a schedule.
- Notice that a biometric identifier is being collected, delivered before collection rather than on a receipt afterwards.
- The specific purpose and the length of term stated in that notice. Both elements are required; naming the purpose without a term is a common and fatal drafting shortcut.
- A written release executed by the individual — a signature or a genuine electronic equivalent on a screen that presents the notice. A pre-checked box on a loyalty enrollment does not qualify.
- No sale or profit from the biometric data, and no disclosure without separate consent. Sharing a template with a fraud-prevention consortium is a disclosure.
- Reasonable storage standards at least as protective as those used for other confidential information — a materially higher bar in a pharmacy than in a gym, because the comparison class is prescription data.
Damages after the 2024 amendment
The single-incident amendment ended the theory that each scan is a separate violation. That was the change that made time-clock cases existential, and its removal genuinely lowers the ceiling. It does not lower the floor. Statutory damages remain per person — negligent and reckless or intentional violations carry different amounts — and a retail pharmacy footprint in Illinois produces a class measured in customers, not in employees. A chain that enrolled face templates at every Illinois location without a posted policy is looking at a class larger than any time-clock case ever certified.
Beyond Illinois
Illinois remains the only state with a private right of action for biometrics, which is why it drives the design. But Texas CUBI and Washington's biometric statute impose consent duties enforced by their attorneys general, Colorado now requires consent for employee biometrics, and most comprehensive state privacy laws treat biometric data as sensitive data requiring opt-in. A national pharmacy chain that builds to BIPA generally clears the others; one that builds to the weakest state and geofences Illinois usually discovers the geofence does not survive a system migration.
Frequently Asked Questions
Does HIPAA exempt a pharmacy from BIPA?
Not broadly. BIPA's exclusions cover information collected for treatment, payment, or health care operations, and patient information in a health care setting. Both are read narrowly and turn on the purpose of the specific collection, not on the identity of the business. A face template used only to confirm the right patient is receiving a dispensed prescription has a real argument. The same camera feeding loss prevention or analytics does not, and employee biometrics fall outside the exclusion entirely.
Does BIPA cover pharmacy employees as well as patients?
Yes, and that is where most pharmacy exposure sits. Fingerprint login at the dispensing workstation, biometric access to the controlled substance safe, and back-room time clocks are all covered collections with no patient-information exclusion available. Each needs written notice, a written release, and a published retention schedule before the first scan.
What exactly is required before the first scan?
A publicly available written policy with a retention schedule and destruction guidelines; written notice that a biometric identifier is being collected and stored; a statement of the specific purpose and the length of term; and a written release executed by the individual. Verbal consent, a posted sign, or a pre-checked box in a loyalty enrollment do not satisfy the release.
How did the 2024 amendment change exposure?
It limited accrual to a single recovery per person per collection method rather than one per scan, which removed the per-transaction multiplication behind the largest time-clock verdicts. The per-person amount is unchanged, so a chain that enrolled face templates across many Illinois counters still faces a class measured in customers.
Can we rely on the biometric vendor's compliance?
No. The notice and release duties run to the entity in possession, which includes the pharmacy operating the terminal even if the template is stored in the vendor's cloud. Vendors have been named as defendants themselves, so both parties are typically exposed and the contract only decides who ultimately pays. Confirm the vendor's own written policy is publicly posted before signing.
Is a photo on file the same as a biometric identifier?
A photograph alone is expressly excluded from BIPA's definition of a biometric identifier. A scan of face geometry derived from that photograph is not. If your system extracts a template to perform matching, you are collecting a biometric identifier regardless of how the source image was described at intake.