Illinois BIPA Rules for Clinics Using Fingerprint Time Clocks: Compliance Checklist
BIPA Applicability for Clinics
Illinois’ Biometric Information Privacy Act (BIPA) applies to private entities, which include medical and dental clinics that use fingerprint time clocks for employees. Fingerprints are expressly defined as biometric identifiers, and entities in possession of such data must follow BIPA’s requirements before and after collection. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K10&utm_source=openai))
Healthcare exemptions are narrow: they cover information captured from a patient in a health care setting or collected for treatment, payment, or operations under HIPAA—not employee time clock scans. In other words, the typical clinic workforce fingerprint program is not exempt from BIPA under the “healthcare” carveout. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K10&utm_source=openai))
- Key backdrop: individuals can sue without proving separate actual harm (Rosenbach), claims have a 5‑year statute of limitations (Tims), and as of August 2, 2024, repeated collections/disclosures of the same person’s data count as a single violation for damage recovery and “written release” can be obtained via electronic signature (SB 2979). ([law.justia.com](https://law.justia.com/cases/illinois/supreme-court/2019/123186.html?utm_source=openai))
Employee Consent Procedures
Before any fingerprint scan is collected, you must provide written notice that explains: (1) that a biometric identifier is being collected or stored; (2) the specific purpose; and (3) the length of time it will be collected, stored, and used. Then obtain a written release from each employee—electronic signatures now satisfy the “written release” requirement. Do not collect any scans until these steps are complete. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K15))
What to include in your notice and release
- Purpose (e.g., timekeeping and fraud prevention) and how the fingerprint template is used.
- The data retention period and the criteria that trigger deletion.
- Who receives the data (e.g., your time clock vendor) and why.
- Acknowledgment that the employee read the policy and grants written consent.
Data Retention and Destruction Policies
Publish a clear policy, available to the public, that sets a data retention period and destruction schedule. You must permanently destroy biometric identifiers and information when the original purpose has been satisfied or within three years of the individual’s last interaction with your clinic—whichever occurs first. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K15))
Data destruction methods and documentation
- Specify approved data destruction methods (for example, cryptographic erasure of databases, secure deletion of backups, and physical destruction of on‑prem devices when decommissioned).
- Maintain a destruction log (date, datasets, method, and personnel) and require your vendor to provide written deletion confirmations.
Prohibited Uses of Biometric Data
You may not sell, lease, trade, or otherwise profit from biometric identifiers or information. Disclosure or redisclosure is prohibited unless the individual consents, the disclosure completes a financial transaction requested by the individual, or disclosure is required by law, warrant, or subpoena. Align all internal and vendor practices to these limits. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K15))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Data Security Requirements
Store, transmit, and protect biometric data using a security program that meets your industry’s reasonable standard of care and is at least as protective as the safeguards you use for other confidential and sensitive information. In practice, this means role‑based access controls, encryption in transit and at rest, key management, monitoring and alerting, and prompt revocation of access on employee departure. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K15))
Vendor Compliance Obligations
Both you and your vendor can have BIPA obligations. Vendors qualify as “private entities” under BIPA when they possess or receive biometric data; courts have allowed claims against third‑party vendors for duties tied to possession, disclosure, and security, while consent duties typically fall on the entity that collects or obtains data from employees. Build contracts that require your vendor to meet BIPA’s retention, destruction, disclosure, and security rules. ([law.justia.com](https://law.justia.com/cases/federal/district-courts/illinois/ilndce/1%3A2022cv03061/415932/31/?utm_source=openai))
What to require from vendors
- A publicly available retention and destruction schedule aligned to your policy, with timely deletion and written deletion certificates.
- No sale or other profit from data; no use outside providing the contracted service; no undisclosed redisclosure.
- Security controls and incident reporting at least as strong as those protecting other confidential data.
- Flow‑down obligations to sub‑processors, plus cooperation with access/deletion requests.
Non-Biometric Time Clock Alternatives
- RFID/proximity badges or swipe cards tied to employee IDs.
- PIN or username/password entry at a kiosk or workstation.
- Secure mobile timekeeping apps with geofencing and attestation (avoid biometric options).
- Photo capture limited to identity verification by a manager (photographs themselves are excluded from “biometric identifiers,” but measurements like face geometry are covered—ensure your system does not extract face geometry). ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K10&utm_source=openai))
FAQs
What are the consent requirements under Illinois BIPA?
Before collecting any fingerprint, you must provide written notice stating that a biometric identifier is being collected, the specific purpose, and the length of time it will be used and stored; then obtain a written release. Since August 2, 2024, an electronic signature counts as the required written release. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K15))
How long must biometric data be retained and when must it be destroyed?
Your publicly available policy must require permanent destruction when the original purpose is satisfied or within three years of the individual’s last interaction with your clinic—whichever comes first. Apply this to production systems and backups, and secure written deletion confirmations from vendors. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K15))
Are clinics liable if their vendor violates BIPA?
Yes, each “private entity” with relevant duties can be liable. Clinics that collect employee fingerprints must meet consent and policy obligations; vendors in possession of biometric data must meet duties related to retention, disclosure, and security. Your contract should allocate responsibilities, but it cannot eliminate statutory obligations. ([law.justia.com](https://law.justia.com/cases/federal/district-courts/illinois/ilndce/1%3A2022cv03061/415932/31/?utm_source=openai))
What penalties apply for non-compliance with BIPA?
BIPA allows a private right of action with statutory damages up to $1,000 per negligent violation or up to $5,000 per reckless or intentional violation, plus attorneys’ fees and injunctive relief. Illinois’ high court set a five‑year statute of limitations for BIPA claims, and a 2024 amendment limits recovery so repeated scans or disclosures of the same person using the same method count as a single violation for damages. ([ilga.gov](https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K20&utm_source=openai))
Conclusion
For clinics using fingerprint time clocks, BIPA compliance hinges on front‑loaded transparency and ongoing governance: give written notice, obtain written consent, publish and follow a tight retention/destruction policy, bar prohibited uses, secure the data, and bind vendors to the same standards. Doing so reduces legal risk while respecting employees’ biometric privacy.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.