LAW.coLAW.co

Townsend v. Estates of Hyde Park

2026-08-31

Summary

Holding. The appellate court answered the certified legal question in the negative, holding that employee hand scans collected through a healthcare facility's timekeeping system do not qualify as exempt healthcare operations under HIPAA and therefore remain subject to the Biometric Information Privacy Act's protections. The cause was remanded for further proceedings consistent with the opinion.

Townsend, a nurse, filed a class action lawsuit alleging that her former employer, a nursing facility called Estates of Hyde Park, violated Illinois's Biometric Information Privacy Act by requiring employees to submit hand scans for timekeeping purposes without proper notice, consent, or data retention practices. The facility argued the hand scans were exempt from the Act because they qualified as healthcare operations under the federal Health Insurance Portability and Accountability Act (HIPAA). The case reached the appellate court through an interlocutory appeal on a certified legal question about whether employee timekeeping biometrics fall within the HIPAA-based exemption.

The court examined the statutory language and regulatory framework underlying both the state biometric law and HIPAA. It concluded that the exemption applies only to biometric information collected for healthcare treatment, payment, or operations that are specifically defined under HIPAA regulations. The court found that employee timekeeping, while occurring at a healthcare facility, is not itself a healthcare operation covered by HIPAA because it does not directly relate to patient care. Under HIPAA regulations, "covered functions"—the activities that define a healthcare provider—do not include support functions like payroll and timekeeping, even though such functions are necessary for the entity to operate.

Summary generated by law.co from the public-domain opinion. The opinion text itself is public domain.

Key issues

  • Whether employee biometric timekeeping data at a healthcare facility qualifies as healthcare operations exempt under HIPAA
  • The proper interpretation of "covered functions" in HIPAA regulations as applied to state biometric privacy law
  • Whether an exemption in the Act applies only to support functions directly related to patient care or broadly to all healthcare facility operations

Procedural posture

This interlocutory appeal came to the appellate court on a certified legal question after the trial court granted the defendant's motion for certification pursuant to Illinois Supreme Court Rule 308, following initial denial of that motion and subsequent reversal by the Illinois Supreme Court's supervisory order.

Authorities cited

No cited authorities resolved to law.co cases yet.

Opinion

majority opinion

2026 IL App (1st) 250096

No. 1-25-0096

Opinion filed August 31, 2026

FIFTH DIVISION

IN THE

APPELLATE COURT OF ILLINOIS

FIRST DISTRICT

DEBRA D. TOWNSEND, Individually and on ) Appeal from the Circuit Court

Behalf of All Others Similarly Situated, ) of Cook County.

)

Plaintiff-Appellee, )

)

v. ) No. 2019 CH 11849

)

THE ESTATES OF HYDE PARK, LLC., ) The Honorable

) Eve M. Reilly,

Defendant-Appellant. ) Judge, presiding.

JUSTICE ODEN JOHNSON delivered the judgment of the court, with opinion.

Presiding Justice Mitchell and Justice Wilson concurred in the judgment and

opinion.

Justice Wilson also specially concurred, with opinion.

OPINION

¶1 On October 15, 2019, Debra Townsend, a nurse, filed a class action complaint against

her former employer, defendant Estates of Hyde Park, a short-term rehabilitation and longterm care facility in Cook County. The complaint alleged numerous violations of the Biometric

Information Privacy Act (Act) (740 ILCS 14/1 et seq. (West 2018)). On February 22, 2024,

defendant moved for judgment on the pleadings, which the trial court denied on July 12, 2024.

However, on December 19, 2024, over plaintiff’s objection, the trial court granted defendant’s

1

motion, pursuant to Illinois Supreme Court Rule 308 (eff. Oct. 1, 2019), which permits a party

to apply to the appellate court for leave to appeal a legal question certified by the trial court.

¶2 On February 24, 2025, a different panel of the Appellate Court, First District, entered

an order denying defendant’s application for leave to appeal. On May 12, 2025, our supreme

court entered an order, pursuant to its supervisory authority, instructing the Appellate Court,

First District, to vacate its denial order. The supreme court further directed the appellate court

to allow defendant’s application and to consider the legal question certified by the trial court.

On July 21, 2025, the panel that had entered the denial order entered a subsequent order

vacating it. On January 2, 2026, the appeal was assigned to this panel for consideration and

decision.

¶3 The question, submitted by defendant and certified by the trial court, asks:

“Is fingerprint or scan of a hand information collected by a healthcare provider from

its employees through its timekeeping system for purposes of complying with Illinois

and/or Federal healthcare regulations ‘information collected, used, or stored for health

care treatment, payment, or operations under the federal Health Insurance Portability

and Accountability Act of 1996 [(HIPAA) (Pub. L. No. 104-191, 110 Stat. 1936

(1996))]’ 740 ILCS 14/10, such that it is carved out from the definition of ‘biometric

identifier’ under the Illinois Biometric Information Privacy Act?”

At the heart of this question are payroll records resulting from a timekeeping system that

collects biometric data. Defendant argues that, since it is required to later submit its payroll

records to federal and state regulatory agencies, then its payroll records qualify as “health care”

operations that are exempt from the Act. In denying defendant’s motion for judgment on the

pleadings, the trial court found defendant’s argument unpersuasive. For the following reasons,

2

we are also unpersuaded and, consequently, answer the certified question in the negative:

defendant’s payroll records are not exempt from the Act. We will not rule on the judgment of

the pleadings, as it is beyond the scope of this appeal, which is limited to the certified question.

¶4 BACKGROUND

¶5 Since this appeal comes to us at the pleadings stage, we accept as true all the wellpleaded facts in the complaint and all reasonable inferences that may be drawn from those

facts, and we construe them in a way most favorable to plaintiff. Bennett v. Chicago Title &

Trust Co., 404 Ill. App. 3d 1088, 1094 (2010). No answer was filed by defendant, and no

exhibits were attached to the complaint. We summarize below the facts alleged in the

complaint.

¶6 Defendant Estates of Hyde Park, LLC is a short-term rehabilitation and long-term care

facility in Cook County, where plaintiff Debra Townsend, a nurse, worked from April 2019 to

September 2019. Handscans were used at the facility for timekeeping purposes.

¶7 When defendant hires an employee, the employee is enrolled in defendant’s employee

database, using a scan of the employee’s hand. Defendant then uses its employee database to

monitor the time worked by its employees. Defendant requires its employees, as a condition

of employment, to have their hand scanned by a biometric timekeeping device. Employees are

required to have their hands scanned “to clock-in and clock-out, recording their time worked.”

Plaintiff alleges that, “[w]hile many employers use conventional methods for tracking time

worked (such as ID badges or punch clocks), Defendant’s employees are required, as a

condition of employment, to have their hand geometry scanned by a biometric timekeeping

device.”

3

¶8 Plaintiff’s complaint alleges that defendant violated the Act in numerous ways, such as

failing to inform employees of the length of time that their scans would be stored and failing

to provide a publicly available retention schedule and guidelines for destruction. Plaintiff

alleges that defendant disclosed employee hand-scan data to at least one third-party vendor. In

her putative class action complaint, filed October 15, 2019, plaintiff sought to bring her action

on behalf of herself and also on behalf of other similarly situated individuals who worked for

defendant and who had hand scans collected.

¶9 In its motion for judgment on the pleadings, defendant argued that the act of scanning

an employee’s hand for timekeeping purposes is excluded from the Act’s protections, on the

ground that the Act exempted from its protections “health care *** operations under

[HIPAA].” 740 ILCS 14/10 (West 2018).

¶ 10 At the May 30, 2024, hearing on defendant’s motion, defendant argued that it had to

submit its “payroll-based records” to state and federal agencies, in order to qualify for federal

government-funded health programs and to maintain its state license as a nursing home, and,

thus, its payroll qualified as a health care operation under the Health Insurance Portability and

Accountability Act of 1996 (HIPAA) (Pub. L. No. 104-191, 110 Stat. 1936 (1996)). In

response, plaintiff argued that the fact that payroll records were sent to a regulator who might

then use them in an audit was too tenuous a connection for them to qualify as health care

operations under HIPAA. Plaintiff noted that every Cook County judge to address the issue

had held that timekeeping was not a health care operation under HIPAA.

¶ 11 On July 5, 2024, the trial court denied defendant’s motion for judgment on the

pleadings. The trial court’s order noted that there was a split among trial courts regarding the

application of the Act to biometric timekeeping systems used in healthcare facilities. The trial

4

court noted that the Illinois Supreme Court’s decision in Mosby v. Ingalls Memorial Hospital,

2023 IL 129081, was instructive but not dispositive, since Mosby involved medication

dispersion rather than the timekeeping of staff. Mosby was the last decision issued by the

Illinois Supreme Court regarding the Act’s reach.

¶ 12 On December 19, 2024, the trial court granted defendant’s motion for Illinois Supreme

Court Rule 308 (eff. Oct. 1, 2019) certification. The trial court also directed that discovery,

which had been stayed since defendant’s first motion, would remain stayed pending the

outcome of the interlocutory appeal. As noted above, on February 24, 2025, a panel of this

court denied defendant’s application for leave to appeal. On March 28, 2025, defendant

petitioned for leave to appeal to the Illinois Supreme Court. On May 28, 2025, the supreme

court denied defendant’s petition for leave to appeal to the supreme court but entered a

supervisory order directing the appellate court to vacate its order denying the interlocutory

appeal. The appellate court was also directed to answer the question certified by the trial court.

After thorough briefing, further motions to cite additional authority, and oral argument, we

answer the certified question below.

¶ 13 ANALYSIS

¶ 14 A. Standard of Review

¶ 15 By definition, certified questions are solely questions of law, which are subject to

de novo review. Mosby, 2023 IL 129081, ¶ 29. Questions of statutory construction are also

questions of law and are also subject to de novo review. Mosby, 2023 IL 129081, ¶ 29. De novo

review means that we owe no deference to the trial court’s decision and that we stand in the

same position as the trial court did. People v. Morgan, 2025 IL 130626, ¶¶ 21-22. We perform

the same analysis that a trial court would. People v. Harris, 2022 IL App (1st) 192509, ¶ 19.

5

However, while we owe no deference to the trial court’s opinion, we remain free to be

persuaded by its logic and reasoning. Eckhardt v. The Idea Factory, LLC, 2021 IL App (1st)

210813, ¶ 15 (even when not binding, a decision may still carry persuasive authority).

¶ 16 The purpose of statutory construction is to give effect to the legislators’ intent, and the

best indication of their intent is the plain and ordinary meaning of the words that they chose to

use. Mosby, 2023 IL 129081, ¶ 30. We construe the statute as a whole and do not view words

or phrases in isolation but rather consider them in light of the statute’s other relevant

provisions. Mosby, 2023 IL 129081, ¶ 30.

¶ 17 When a statute’s language is plain and unambiguous, we do not depart from it by

reading into it exceptions, limits or conditions that the legislators did not state. Mosby, 2023

IL 129081, ¶ 31. However, in construing a statute, we consider the reason for the law, the

problems that the legislators sought to remedy, the purposes they were trying to achieve, and

the consequences if we construe the statute one way or another. Mosby, 2023 IL 129081, ¶ 31.

In addition, each word in a statute is to be interpreted in such a way that it is given meaning

and not rendered superfluous. Mosby, 2023 IL 129081, ¶ 36.

¶ 18 B. Legislative Purpose

¶ 19 The Act has a section conveniently titled “Legislative findings; intent,” to tell readers

what the legislators’ purpose was, when they passed the Act in 2008. 740 ILCS 14/5 (West

2018); 740 ILCS 14/5 (West 2008). This section has remained unchanged by the legislature

since the statute was enacted in 2008. The legislators observed that biometrics are unlike other

unique identifiers, in that once they are compromised, “the individual has no recourse.” 740

ILS 14/5(c) (West 2018). Further, “[t]he full ramifications of biometric technology are not

fully known.” 740 ILS 14/5(f) (West 2018). Based on these concerns, the legislators found that

6

the public welfare would best be served “by regulating the collection, use, safeguarding,

handling, storage, retention, and destruction of biometric identifiers.” 740 ILS 14/5(g) (West

2018).

¶ 20 In its reply brief, defendant argues that, because the question that it framed states “for

purposes of,” the primary purpose of the data is now beyond question and beyond this court’s

power to consider. However, one action may have many purposes and may have different

purposes to different entities. That this may have been one of defendant’s purposes does not

relieve us of the duty of analyzing the intent of the statute and its related regulations.

¶ 21 C. Biometric Identifier

¶ 22 The Act explicitly defines the term “ ‘Biometric identifier’ ” to include a “scan of

hand.” 740 ILCS 14/10 (West 2018). Thus, there is no dispute that hand scans were generally

meant to be included within the term “ ‘Biometric identifier.’ ” 740 ILCS 14/10 (West 2018).

¶ 23 However, section 10 of the Act exempts certain limited information from the

“biometric identifier” category that would otherwise be included in it. 740 ILCS 14/10 (West

2018). Significant to this appeal, section 10 states: “Biometric identifiers do not include

information captured from a patient in a health care setting or information collected, used, or

stored for health care treatment, payment, or operations under [HIPAA].” 740 ILCS 14/10

(West 2018). In the case at bar, defendant argued to the trial court that its employee handscans

were biometric information collected, used and stored “for health care *** operations.” 740

ILCS 14/10 (West 2018). However, the exemption does not apply to all healthcare operations,

but only to those healthcare operations “under [HIPAA].” 740 ILCS 14/10 (West 2018).

¶ 24 As we noted above, every word or phrase in a statute must be interpreted in a way that

gives it meaning and does not render it superfluous. Mosby, 2023 IL 129081, ¶ 36. If the

7

legislators had intended the exemption to apply to all health care operations, they could have

ended the exemption with the word “operations.” Thus, the additional phrase “under [HIPAA]”

is a limiting phrase carving out some operations from the exemption’s reach.

¶ 25 In Mosby, our supreme court found that the exemption did apply to finger scans

collected from nurses to access patient medicine. Mosby, 2023 IL 129081, ¶ 54. However, the

supreme court ended its opinion with a strongly worded caveat that it was not construing the

language at issue as a broad, categorical exemption for biometric identifiers taken from health

care workers:

“We are not construing the language at issue as a broad, categorical exclusion of

biometric identifiers taken from health care workers. Here, the nurses’ biometric

information, as alleged in the complaints, was collected, used, and stored to access

medications and medical supplies for patient health care treatment and is excluded from

coverage under the Act because it is information, collected, used, or stored for health

care treatment, payment, or operations under [HIPAA].” (Internal quotation marks

omitted.) Mosby, 2023 IL 129081, ¶ 57.

In the case at bar, if we interpret these payroll handscans to be excluded as well, it is hard to

imagine what, if anything, would be left to be covered under the Act, and the exemption would

become the “broad, categorical exclusion of biometric identifiers taken from health care

workers” that our supreme court warned against. Mosby, 2023 IL 129081, ¶ 57. Defendant’s

“hail-Mary-pass” argument at the end of its brief that employers still could not market or sell

their employees’ data does little to alter this conclusion.

¶ 26 Where the legislators wanted to create blanket exclusions for certain sectors of the

workforce, they expressly provided for it. For example, the Act does not apply either to

8

financial institutions subject to Title V of the federal Gramm-Leach-Bliley Act (Pub. L. No.

106-102, 113 Stat. 1338 (1999)) or to employees, contractors, or subcontractors of local

government or the State. 740 ILCS 14/25(c), (e) (West 2018). No such blanket exclusion exists

for health care, and the Mosby court was clear that it did not intend to read one into an act

where none existed. Mosby, 2023 IL 129081, ¶ 57.

¶ 27 The trial court found, and we agree, that HIPAA regulations’ definition of “health care

*** under [HIPAA]” (740 ILCS 14/10 (West 2018)) is specific to the health care of an

individual, as opposed to a system. Our supreme court turned to HIPAA regulations to define

health care under HIPAA (Mosby, 2023 IL 129081, ¶ 49), and the trial court followed its lead

and did the same. See Mosby, 2023 IL 129081, ¶ 52 (“the legislature was directing readers to

HIPAA to discern the meaning of” health care operations). HIPAA regulations define “Health

care” as follows:

“Health care means care, services, or supplies related to the health of an individual.

Health care includes, but is not limited to, the following:

(1) Preventive, diagnostic, therapeutic, rehabilitative, maintenance, or

palliative care, and counseling, service, assessment, or procedure with respect to the

physical or mental condition, or functional status, of an individual or that affects the

structure or function of the body; and

(2) Sale or dispensing of a drug, device, equipment, or other item in

accordance with a prescription.” (Emphases added and in original.) 45 C.F.R.

§ 160.103 (eff. Mar. 24, 2026).

The above regulation was quoted by our supreme court when defining the reach of health care

under HIPAA. Mosby, 2023 IL 129081, ¶ 49. While the finger scans in Mosby for “dispensing”

9

a patient’s medicine fit squarely in paragraph (2) above (Mosby, 2023 IL 129081, ¶ 49 (noting

the applicability of this paragraph)), we see nothing in the above definition to cover employee

tracking. The definition above clearly states that “[h]ealth care” means care “related to the

health of an individual,” just as the trial court found. (Emphasis omitted.) 45 C.F.R. § 160.103

(2026).

¶ 28 HIPAA’s definition of “Health care operations” does not help defendant either. HIPAA

regulations state: “Health care operations means any of the following activities of the covered

entity to the extent that the activities are related to covered functions ***.” (Emphasis in

original.) 45 C.F.R. § 164.501 (2013). Defendant argues that “the following activities” include

“auditing functions, including fraud.” 45 C.F.R. § 164.501 (2013). However, defendant’s

argument overlooks the fact that the listed activities qualify only “to the extent that the

activities are related to covered functions.” 45 C.F.R. § 164.501 (2013). “Covered functions”

is a term of art that is specifically defined in the regulations. (Emphasis omitted.) 45 C.F.R.

§ 164.103 (2013). “Covered functions means those functions of a covered entity the

performance of which makes the entity a health plan, health care provider, or health care

clearinghouse.” (Emphasis omitted.) 45 C.F.R. § 164.103 (2013). As the trial court concluded,

and we agree, employee timekeeping is not the type of function, the performance of which

makes defendant a health care provider. Timekeeping is not intrinsic to healthcare; it is part of

a myriad number of businesses and employers with no relation to healthcare.

¶ 29 Defendant directs our attention to the issue of the Federal Register that added the term

“covered functions.” Standards for Privacy of Individually Identifiable Health Information, 65

Fed. Reg. 82462, 82489 (Dec. 28, 2000). Page 82489 states:

10

“We add a new term ‘covered functions,’ as a shorthand way of expressing and

referring to the functions that the entities covered by section 1172(a) of the Act

perform. Section 1171 defines the terms ‘health plan’, ‘health care provider’, and

‘health care clearinghouse’ in functional terms. Thus, a ‘health plan’ is an individual

or group plan ‘that provides, or pays the cost of, medical care * * *’, a ‘health care

provider’ ‘furnish[es] health care services or supplies,’ and a ‘health care

clearinghouse’ is an entity ‘that processes or facilitates the processing of * * * data

elements of health information * * *’. Covered functions, therefore, are the activities

that any such entity engages in that are directly related to operating as a health plan,

health care provider, or health care clearinghouse; that is, they are the functions that

make it a health plan, health care provider, or health care clearinghouse.” (Emphasis

added.) Standards for Privacy of Individually Identifiable Health Information, 65 Fed.

Reg. at 82489.

Applying the definition above, payroll records and timekeeping are not the functions that make

defendant a health care provider.

¶ 30 If we had any doubt, which we do not, that doubt is erased by the very next line in the

Federal Register: “The term ‘covered functions’ is not intended to include various support

functions, such as computer support, payroll and other office support, and similar support

functions, although we recognize that these support functions must occur in order for the entity

to carry out its health care functions.” (Emphases added.) Standards for Privacy of Individually

Identifiable Health Information, 65 Fed. Reg. at 82489. Thus, per the quote above, the payroll

records that defendant must submit to various government agencies are not part of defendant’s

covered functions, although they “must occur in order for [defendant] to carry out its health

11

care functions.” Standards for Privacy of Individually Identifiable Health Information, 65 Fed.

Reg. at 82489.

¶ 31 There is another problem with defendant’s argument that plaintiff notes in her brief.

Our analysis above is premised on the assumption that the data generated from defendant’s

biometric timekeeping device is the same data that is then used to generate the payroll reports

sent to federal and state regulatory agencies. However, at this stage, all we have in front of us

are plaintiff’s allegations in her complaint, and there are no such allegations in her complaint.

Thus, even if we were persuaded by defendant’s argument, which we are not, we still could

not rule in its favor at this early stage of the litigation, without any evidentiary support for this

missing link in defendant’s argument. Cline v. Marion Rehabilitation & Nursing Center, LLC,

2025 IL App (5th) 240784-U, ¶¶ 34-37 (evidentiary support was needed to show that the

biometric data was the same data submitted in audits and reports); Verity v. Herrin

Rehabilitation & Nursing Center, LLC, 2025 IL App (5th) 240785-U, ¶¶ 37-38.

¶ 32 A close reading of the pertinent regulations and Mosby requires us to answer the

certified question in the negative and find that the Act does not exempt the handscans used by

defendant for timekeeping. One of the many problems with defendant’s argument is that it

creates an all-encompassing exemption regarding healthcare workers and, thus, categorically

eliminates protections for them, in direct contravention of the supreme court’s warning in

Mosby.

¶ 33 CONCLUSION

¶ 34 For the foregoing reasons, we answer the question in the negative and remand for

further proceedings consistent with this opinion.

¶ 35 Certified question answered; cause remanded.

12

¶ 36 JUSTICE WILSON, specially concurring:

¶ 37 I concur in the court’s opinion and join its holding. I write separately to emphasize the

narrow scope of the Biometric Information Privacy Act’s (Act) (740 ILCS 14/1 et seq. (West

2018)) health care exemption and to emphasize the patient-specific linkage that HIPAA

requires. The statutory text and structure, reinforced by controlling precedent, foreclose any

reading that would convert general workforce timekeeping into HIPAA “health care

operations,” and thus exempt it from the Act.

¶ 38 The Act exempts biometric identifiers only when “collected, used, or stored for health

care treatment, payment, or operations under [HIPAA]” (740 ILCS 14/10 (West 2018)), which,

by HIPAA’s design, centers on care “related to the health of an individual” and thus demands

a patient-specific focus. HIPAA expressly excludes employment records maintained by a

covered entity in its role as employer. Biometric timekeeping, attendance, and payroll data are

employment records, not PHI, and therefore are outside HIPAA’s regulatory scope and outside

the Act’s exemption.

¶ 39 HIPAA protects protected health information (PHI), which is individually identifiable

health information created or used in connection with a patient’s medical care; by contrast,

employment records—even when held by a hospital—are excluded from PHI. Biometric scans

used solely to clock employees in or out, verify attendance, allocate hours, or administer

payroll do not concern the care of any individual patient and are not PHI.

¶ 40 HIPAA’s “health care operations,” as defined in 45 C.F.R. § 164.501 (2013), include

compliance, quality assessment, auditing, and business-management activities only insofar as

those activities involve or depend upon PHI tied to identifiable patients; they do not convert

general workforce management into HIPAA operations when no patient-specific information

13

is involved. The statute’s structure confirms that HIPAA’s operational allowances exist to

facilitate the lawful handling of PHI, not to broadly exempt employment-related biometric

collection from state biometric privacy laws.

¶ 41 The Illinois Supreme Court in Mosby v. Ingalls Memorial Hospital, 2023 IL 129081,

held that employee biometrics may fall within the Act’s exemption only when the biometric

capture is functionally and documentarily tied to HIPAA-defined purposes—for example,

using biometrics to access a named patient’s medications or clinical records—rejecting any

blanket, industry-wide exemption. Mosby confirms that general employee administration

cannot trigger the Act’s exemption, absent a demonstrable linkage to identifiable patient PHI

in HIPAA-defined treatment, payment, or operations. Statutory or regulatory mandates to track

staffing ratios or hours do not transform workforce biometric collection into HIPAA operations

unless the reporting itself requires identifiable patient PHI; workforce-level reporting remains

an employment function and does not escape the Act.

¶ 42 As indicated above, the core health care activities of “Treatment,” “Payment,” and

“Health Care Operations” are limited to the activities listed in the definition of “health care

operations” at 45 C.F.R. § 164.501 (2013). As further explicitly stated in the regulation:

“The HIPAA Privacy Rule establishes a foundation of Federal protection for personal

health information, carefully balanced to avoid creating unnecessary barriers to the

delivery of quality health care. As such, the Rule generally prohibits a covered entity

from using or disclosing protected health information unless authorized by patients,

except where this prohibition would result in unnecessary interference with access to

quality health care or with certain other important public benefits or national priorities.

Ready access to treatment and efficient payment for health care, both of which require

14

use and disclosure of protected health information, are essential to the effective

operation of the health care system. In addition, certain health care operations—such

as administrative, financial, legal, and quality improvement activities—conducted by

or for health care providers and health plans, are essential to support treatment and

payment. Many individuals expect that their health information will be used and

disclosed as necessary to treat them, bill for treatment, and, to some extent, operate the

covered entity’s health care business. To avoid interfering with an individual’s access

to quality health care or the efficient payment for such health care, the Privacy Rule

permits a covered entity to use and disclose protected health information, with certain

limits and protections, for treatment, payment, and health care operations activities.”

Uses and Disclosures for Treatment, Payment, and Health Care Operations, U.S.

Dep’t of Health and Hum. Services (rev. Apr. 3, 2003), https://www.hhs.gov/hipaa/forprofessionals/privacy/guidance/disclosures-treatment-payment-health-careoperations/index.html [https://perma.cc/A97C-37SV] (HHS’s discussion of 45 C.F.R.

§ 164.506).

¶ 43 With that guidance, biometric authentication to access patient-specific medications—

such as a nurse’s fingerprint unlocking a dispensing cabinet for an identified patient, with the

event recorded in controlled-substance logs tied to that patient—qualifies as HIPAA-regulated

activity. Biometric access to a specific patient’s electronic health record, where the

authentication event forms part of the PHI audit trail, falls within HIPAA-defined operations.

Fingerprint activation of a medication-administration workstation, enabling wristband

scanning and documentation in an identified patient’s medication administration record, is

patient-linked and within HIPAA. Biometric access control to restricted clinical areas housing

15

identifiable patient records or treatment materials, with logs used for PHI-related compliance,

constitutes HIPAA operations. Fingerprint scanning embedded in the controlled-substance

chain of custody for a specific patient prescription is a HIPAA-regulated use.

¶ 44 The governing rule is narrow and administrable: the Act’s health-care exemption

applies when, and only when, the biometric collection is used for HIPAA-defined treatment,

payment, or health-care operations and is tied to the PHI of identifiable patients; biometric

timekeeping and generalized workforce administration remain subject to the Act’s notice,

consent, retention, and security obligations. Defendants argue that they collect subject

biometric data as part of their statutory or regulatory mandates to track staffing compliance.

Whether that conduct qualifies as an Act exemption will be determined through the litigation

process. However, the certified question, as presented, makes no provision for the patientspecific linkage that HIPAA requires and thus must be answered in the negative.

¶ 45 I therefore respectfully concur.

16

Townsend v. Estates of Hyde Park, LLC, 2026 IL App (1st) 250096

Decision Under Review: Appeal from the Circuit Court of Cook County, No. 2019-CH11849; the Hon. Eve M. Reilly, Judge, presiding.

Attorneys Bonnie Keane DelGobbo, Joel Griswold, and Katharine for Walton, of Baker & Hostetler LLP, of Chicago, for appellant. Appellant:

Attorneys James B. Zouras, Ryan F. Stephan, and Andrew C. Ficzko, of for Stephan Zouras, LLC, of Chicago, for appellee.

Appellee:

17