Illinois med spa owners spend their compliance budget on the corporate practice of medicine, which is correct, and then get sued over a facial-analysis camera.
Illinois is the only state in the country where a private individual can sue you directly for mishandling biometric data, without showing any harm at all, for one to five thousand dollars a person. That is the Biometric Information Privacy Act, and a med spa is a near-perfect defendant: face scans at the front desk, skin-mapping devices in the treatment room, and fingerprint time clocks in the break room.
Two problems, then. Take them in order.
Problem one: Illinois applies the corporate practice of medicine
The Illinois Medical Corporation Act limits ownership of a corporation organized to practice medicine to licensed physicians. Illinois courts have recognized the corporate practice doctrine for decades, with carve-outs — most notably for licensed hospitals — that do not extend to an aesthetics business.
The standard answer is the two-entity split: a physician-owned medical entity delivering medical services, and a separately owned company handling facials, waxing, retail, marketing and premises. That is the PC-MSO structure, and in Illinois it is not optional decoration.
Illinois has a second lawful path: APRN full practice authority
Unlike Texas, California or New York, Illinois allows an APRN who has obtained full practice authority to own and operate the clinical entity. Under the Illinois Nurse Practice Act, an APRN qualifies by filing an attestation of at least 250 hours of continuing education or training in their certification area and at least 4,000 hours of clinical experience after first attaining national certification.
An APRN with full practice authority may practice without a written collaborative agreement, including prescribing controlled substances as provided by statute. That is a genuinely different ownership route, and it is the reason Illinois should not be lumped in with California in a national compliance chart.
It is also a threshold, not a formality. Confirm the attestation is on file with the Department before you build a company around it.
Problem two: BIPA
The Biometric Information Privacy Act, 740 ILCS 14, was enacted in 2008 and remains the most aggressive biometric privacy statute in the United States. It regulates private entities’ collection, storage, use and disclosure of biometric identifiers and biometric information.
What makes it dangerous is the private right of action. There is no regulator to negotiate with and no requirement to prove injury.
What in a med spa is biometric, and what is not
The distinction is narrower than people assume, in both directions.
| Thing you do | Likely BIPA relevance |
|---|---|
| Ordinary before-and-after photograph | A photograph alone is generally not a biometric identifier |
| Skin-analysis or facial-mapping device that derives face geometry | A scan of face geometry is squarely within the statute |
| Facial recognition check-in or client matching | Within the statute |
| Fingerprint or handprint staff time clock | Within the statute, and the classic BIPA case |
| Voice-print phone or scheduling system | Voiceprints are enumerated in the statute |
| AI photo tool that groups clients by face | Within the statute; this theory produced a nine-figure settlement against a major platform |
The trap is that the device vendor, not the clinic, chose to derive face geometry — and the clinic is the one holding the client relationship.
What BIPA requires before you collect anything
- A written, publicly available policy setting a retention schedule and destruction guidelines
- Written informed consent, obtained before collection, stating the specific purpose and the length of time the data is collected, stored and used
- No selling, leasing or otherwise profiting from biometric data
- No disclosure without consent or another statutory basis
- A reasonable standard of care in storage and transmission
Note that the consent must be written and must precede collection. A general HIPAA authorization does not satisfy it, and a clickwrap buried in an intake form frequently does not either.
Damages, and the 2024 change that helps you
Statutory damages are $1,000 per violation for negligence and $5,000 for intentional or reckless violation. For years, plaintiffs argued each individual scan was a separate violation, which turned a fingerprint time clock into an existential number for a small employer.
On August 2, 2024, Illinois enacted SB 2979, eliminating per-scan accrual: for notice-and-consent and disclosure violations, a defendant is liable for one violation per person regardless of how many scans occurred. In 2026 the Seventh Circuit held that this damages limitation applies retroactively.
This is a real improvement in exposure and it changes nothing about your obligations. One violation per person, multiplied by a client list, is still a serious number.
A practical Illinois checklist
| Area | What to confirm |
|---|---|
| Entity | Physician-owned medical corporation, or an APRN with full practice authority on file |
| Management agreement | Fixed fee, no clinical control by the management company |
| Devices | Ask every vendor in writing whether the device derives face or body geometry |
| Consent | Separate written biometric consent, signed before first capture |
| Policy | Published retention schedule and destruction guidelines |
| Staff | Time clocks and door access audited for biometric capture |
| Vendors | Contracts addressing biometric handling, plus a BAA where PHI is involved |
The vendor question is the one most operators have never asked. Ask it in writing and keep the answer.
How MDside handles Illinois
We place Illinois-licensed physicians and structure the medical entity and management agreement to Illinois law rather than a national template, and we flag the biometric question during onboarding because it does not appear on any med spa compliance checklist we have seen. Where AI tools touch the record, the vendor agreements get the same treatment.
Related reading
- Arizona May Not Require You to Have a Medical Director
- AI Scribes and the Clinical Record: What Still Has to Be True
- New Jersey Already Punished the Sham PC. Read the Case.
- Friendly PC and MSO: How Non-Physicians Legally Operate a Medical Practice
Frequently asked questions
Can a non-physician own a med spa in Illinois?
Not the entity delivering medical services. That must be physician-owned, or owned by an APRN who holds full practice authority. A separate company may own the non-medical side.
Do before-and-after photos violate BIPA?
A photograph by itself is generally not a biometric identifier. A scan of face geometry derived from that image is. The device and software decide the answer, not the camera.
What are BIPA damages?
$1,000 per negligent violation and $5,000 per intentional or reckless violation, with a private right of action. Since the 2024 amendment, notice-and-consent claims accrue once per person rather than per scan.
Does HIPAA consent cover biometric collection?
No. BIPA requires its own written informed consent, obtained before collection, stating purpose and duration.
Can an Illinois APRN own a med spa?
An APRN with full practice authority — 250 hours of continuing education plus 4,000 post-certification clinical hours, attested to the Department — may practice without a collaborative agreement and own the clinical entity.
General information about Illinois practice structure and biometric privacy law, not legal advice. BIPA case law is moving quickly and the statutes change. Confirm your obligations with counsel licensed in Illinois.