Get Security Assessment

HIPAA Compliance in Illinois: BIPA & Healthcare Privacy

Illinois healthcare organizations must comply with federal HIPAA plus state-specific privacy laws, most notably the Biometric Information Privacy Act (BIPA). This guide covers BIPA, the Personal Information Protection Act, Mental Health Code, and other Illinois requirements that extend beyond HIPAA.

Quick Answer

Illinois imposes healthcare privacy through multiple frameworks: HIPAA (federal), BIPA (biometric data rights), Personal Information Protection Act, and Mental Health Code. Most notably, BIPA (740 ILCS 14) is unique among state laws—it grants Illinois residents privacy rights in their biometric data (fingerprints, retinal scans, facial recognition, voice recognition) with a private right of action. Healthcare organizations collecting biometric data (e.g., fingerprint-based access, facial recognition for authentication) must comply with BIPA's strict requirements: informed written consent, secure storage, and deletion procedures. BIPA violations allow lawsuits with statutory damages ($1,000-$5,000 per violation), making BIPA compliance critical. Additionally, Illinois requires prompt breach notification and protects mental health records with strict confidentiality requirements.

How Illinois Law Extends Beyond HIPAA

Illinois law creates unique compliance obligations, particularly through BIPA:

1. Illinois Biometric Information Privacy Act (BIPA - 740 ILCS 14)

BIPA is the strictest biometric privacy law in the nation and applies to healthcare organizations collecting biometric data:

2. Illinois Personal Information Protection Act (815 ILCS 530)

Applies to healthcare organizations handling personal information of Illinois residents:

3. Illinois Mental Health Code (405 ILCS 5/1-119)

Healthcare-specific mental health privacy protections:

4. Illinois Data Breach Notification Law

Specific requirements for healthcare data breaches:

Key Illinois State Statutes & References

740 ILCS 14 (Biometric Information Privacy Act - BIPA)
Establishes strict privacy rights for biometric data. Requires informed written consent, secure storage, and deletion procedures. Provides private right of action with statutory damages $1,000-$5,000 per violation.
815 ILCS 530 (Personal Information Protection Act)
Requires breach notification without unreasonable delay for breaches of personal information including health data. Applies to all entities handling Illinois residents' data.
405 ILCS 5/1-119 (Illinois Mental Health Code - Confidentiality)
Protects confidentiality of mental health treatment records. Requires written authorization for disclosure. Therapist-patient privilege extends beyond HIPAA protections.
405 ILCS 70 (Substance Abuse Treatment Confidentiality)
Protects confidentiality of substance abuse treatment information. Implements federal 42 CFR Part 2 plus additional Illinois requirements.
720 ILCS 5/16-2 (Unauthorized Access to Stored Communications)
Criminalizes unauthorized access to personal information including health data. Healthcare data breaches can trigger criminal liability.
Illinois Attorney General Authority (815 ILCS 505)
Grants Illinois AG authority to pursue unfair or deceptive healthcare privacy practices and healthcare data protection violations.

Illinois Attorney General Enforcement

Illinois enforces healthcare privacy laws through multiple mechanisms:

BIPA enforcement trend: BIPA has triggered hundreds of lawsuits against healthcare providers, retailers, and vendors. Healthcare organizations using biometric authentication, fingerprint scanners, or facial recognition have faced substantial class action litigation. Settlements typically include statutory damages, attorney fees, and requirement to implement compliant biometric policies.

Comparison: HIPAA vs. Illinois State Requirements

Area HIPAA Illinois Law More Stringent
Biometric Data Protected as PHI; standard HIPAA rules BIPA: Strict consent, notice, retention, deletion; private right of action Illinois (significantly)
Biometric Consent General authorization acceptable BIPA: Specific written consent required; must disclose purpose and retention Illinois
Biometric Retention Based on business need BIPA: Maximum 3 years from last use; must destroy thereafter Illinois
Breach Notification 60 days of discovery Without unreasonable delay Illinois
Private Right of Action (Biometric) No private HIPAA right for patients BIPA: Statutory damages $1,000-$5,000 per violation, no cap Illinois (unique)
Mental Health Records Psychotherapy notes protections Illinois: Stricter; even court orders cannot compel disclosure without consent Illinois
Law Enforcement Notification Not required If 250+ IL residents affected or identity theft risk Illinois
Statutory Damages Availability Civil penalties only to HHS BIPA allows individual lawsuits with statutory damages Illinois

Illinois-Specific Breach Notification & BIPA Requirements

Data Breach Notification Timeline

BIPA-Specific Requirements

BIPA Violations Liability

Frequently Asked Questions

If we use fingerprint scanners or facial recognition in our healthcare facility, what BIPA compliance is required? +

If you collect biometric data (fingerprints, facial scans, voiceprints, etc.) from Illinois patients or residents, BIPA compliance is mandatory. You must: (1) Obtain specific, written, informed consent before collection—explain what biometric data will be collected, why, how long it's retained, and how it will be used; (2) Provide public notice of biometric retention and use policies; (3) Maintain reasonable security for stored biometric data; (4) Destroy the biometric data within 3 years of last use or when the stated purpose is satisfied. Failure to comply exposes you to lawsuits by each individual affected, with statutory damages of $1,000-$5,000 per violation. Multiple individuals in a class action could result in millions in liability.

Does BIPA apply only to Illinois companies, or out-of-state providers too? +

BIPA applies to any entity collecting biometric data from Illinois residents, regardless of where the company is located. If you're an out-of-state healthcare provider offering telemedicine or services to Illinois residents, and you collect any biometric data (even a single fingerprint for an Illinois patient), BIPA applies. This broad applicability has led to widespread BIPA litigation against national healthcare providers, vendors, and contractors. Many out-of-state organizations were surprised to discover BIPA liability when Illinois residents filed lawsuits.

What's the practical impact of BIPA's 3-year retention requirement? +

BIPA requires destruction of biometric data within 3 years of last use or when the stated purpose is satisfied, whichever is sooner. For healthcare organizations, this means: (1) If you collect fingerprints for employee access control, you must delete them 3 years after the employee leaves; (2) If you collect facial recognition for patient authentication, you must delete the data 3 years after the last patient interaction; (3) You must establish documented destruction procedures. Failure to delete results in BIPA violations for each individual. This creates operational challenges—organizations must implement systems to track collection dates and automatically flag data for deletion. Many healthcare organizations have had to overhaul their biometric systems to comply.

Can Illinois residents sue directly for BIPA violations, or must I wait for government enforcement? +

Illinois residents have a private right of action—they can sue directly for BIPA violations without any government enforcement. This is unique among privacy laws and makes BIPA distinctly more dangerous. If you violate BIPA, affected individuals can file lawsuit seeking statutory damages of $1,000 per unintentional violation or $5,000 per intentional violation, plus actual damages and attorney fees. There is no cap on total liability. This has led to massive class action lawsuits in Illinois, with healthcare organizations, retailers, and technology companies facing liability for hundreds of thousands or millions of dollars. The threat of private litigation makes BIPA compliance critical.

Protect Your Organization from BIPA & Illinois Privacy Liability

BIPA violations expose your healthcare organization to individual lawsuits with statutory damages and no liability cap. Get a professional security assessment to ensure compliance with BIPA, HIPAA, and Illinois privacy laws.

Get Your Security Assessment