Illinois operators budget for the corporate practice of medicine, which is correct, and then get sued over a facial-analysis camera.
Two problems, and the second one is not on any med spa compliance checklist we have seen. The Biometric Information Privacy Act gives a private individual the right to sue you directly, without showing any harm, for $1,000 per negligent violation and $5,000 per intentional or reckless one.
What Illinois actually requires
- A physician-owned medical corporation under the Illinois Medical Corporation Act — or an APRN who holds full practice authority, attested with at least 250 hours of continuing education and 4,000 post-certification clinical hours.
- A management agreement that leaves clinical decisions with the clinical entity.
- A written, publicly available biometric policy with a retention schedule and destruction guidelines.
- Written informed consent obtained before collection, stating purpose and duration. A HIPAA authorization does not satisfy BIPA.
- A written answer from every device vendor on whether their equipment derives face or body geometry. Most operators have never asked.
Who may do what in Illinois
| License | What they may do |
|---|---|
| Ordinary before-and-after photograph | Generally not a biometric identifier |
| Skin-analysis device deriving face geometry | Squarely within BIPA |
| Facial recognition check-in or client matching | Within BIPA |
| Fingerprint or handprint staff time clock | Within BIPA — the classic case |
| AI photo tool that groups clients by face | Within BIPA; this theory produced a nine-figure settlement |
SB 2979, signed August 2, 2024, ended per-scan damages accrual, and in 2026 the Seventh Circuit held that limitation retroactive. That is a real reduction in exposure and it changes none of your obligations — one violation per person, multiplied by a client list, is still a serious number.
What MDside provides in Illinois
- Illinois-licensed physicians and a medical entity built to Illinois law rather than a national template.
- Confirmation of whether the APRN full-practice-authority route is open to you, and whether the attestation is actually on file.
- The biometric question raised during onboarding, including the vendor letters, the consent form and the published retention policy.
- Vendor agreements reviewed where AI tools touch the clinical record, with a BAA wherever PHI is involved.
- Licensed providers, pharmacy sourcing and lab draws.
See everything that is included, or book a call and tell us which states you operate in.
Read the detail on Illinois
Frequently asked questions
Can a non-physician own a med spa in Illinois?
Not the entity delivering medical services. That must be physician-owned, or owned by an APRN holding full practice authority. A separate company may own the non-medical side.
Do before-and-after photos violate BIPA?
A photograph by itself is generally not a biometric identifier. A scan of face geometry derived from that image is. The device and software decide the answer, not the camera.
Does HIPAA consent cover biometric collection?
No. BIPA requires its own written informed consent, obtained before collection, stating the purpose and the duration of collection, storage and use.
General information about Illinois practice structure and med spa regulation, not legal advice. Statutes, board rules and scope-of-practice requirements change. Confirm your obligations with healthcare counsel licensed in Illinois.