Three states have narrowed biometric privacy law for security systems
Texas amended its biometric privacy statute effective January 1, exempting AI systems deployed to prevent, detect, or respond to security incidents, fraud, harassment, or other illegal activity. The change arrived as part of the state's new AI governance act, and the Security Industry Association read it as the clarity the industry had been asking for.
It's an odd place for that to land. Texas has collected the two largest biometric privacy settlements ever recorded, $1.4 billion from Meta in 2024 and $1.375 billion from Google last year, both under the same statute it just carved a hole in. Both were attorney general actions, and both landed on platforms rather than on anybody running a camera at a door.
That's the third piece of good news in three years for anyone deploying cameras or screening in a hospital, and most of the field is still being told the opposite.
The Illinois law everyone worries about mostly doesn't reach hospitals
The Biometric Information Privacy Act, Illinois BIPA, is the statute that built the biometric class action industry and the one named in every conference session on this subject. It also has a health care carve-out written into its definitions. Information collected, used, or stored for treatment, payment, or operations under HIPAA isn't a biometric identifier under the act at all.
In 2023 the Illinois Supreme Court decided Mosby v. Ingalls Memorial Hospital, brought by nurses over the fingerprint scanners on medication dispensing cabinets, and held that the carve-out isn't limited to patient data. Staff authentication at an Illinois hospital sits largely outside BIPA.
A 2023 ruling had also let a fresh violation accrue on every individual scan, which on a badge reader running two shifts is a number with no ceiling, and that's where most of the settlement pressure came from. The legislature capped it in 2024 at one violation per person per method, and this April the Seventh Circuit held in Clay v. Union Pacific that the cap reaches cases already on file. Statutory damages are still $1,000 for negligence and $5,000 for intentional conduct, but they attach per person now.
Washington's My Health My Data Act is the one that deserves real attention, since it treats biometric data as health data, requires opt-in consent, and unlike Texas it lets private plaintiffs sue. It carries its own security exception, and practitioners reading it have concluded that cameras running facial recognition for security purposes sit inside that exception as long as the data isn't used for anything else.
The exemptions may not cover the lobby camera
Every one of these carve-outs depends on the security purpose holding. Texas data captured under the exemption and later used for another commercial purpose falls back under the consent and notice rules, and the Washington reading rests on the same condition. Illinois is different in kind, because treatment, payment, and operations is a defined HIPAA term and a visitor screening camera in a lobby isn't obviously any of the three. Nobody has litigated that question.
The FTC case against Evolv was about advertising
None of the enforcement that actually reshaped this market was privacy enforcement.
The FTC alleged that Evolv Technologies had advertised that its scanners would detect all weapons while ignoring harmless personal items, and that in practice they missed weapons in schools while alarming on laptops, binders, and water bottles. The stipulated order entered in December 2024 carried no money. It banned unsupported detection claims and gave a defined group of school customers a window to cancel their contracts. Of the 65 education customers eligible to walk, 5 took it.
What a procurement file needs
The privacy statutes have been narrowing since 2023 and the deployment claim hasn't narrowed at all.
A hospital that puts in weapons detection will be asked, after an incident, what it believed the system would catch and where that belief came from. The FTC found that Evolv's customers had been told something the product couldn't do. A purchase order that repeats a marketing claim with no substantiation behind it puts the institution about where the vendor was, except that the institution is the one defending the negligent security claim. That substantiation is something a vendor can hand over during the demo, and it's a great deal harder to assemble two years later with a plaintiff's expert reading the file.
Touring
Don't just tag it, document
A red tag on a sprinkler valve means part of the system is out of service. NFPA 25 wants one on the valve and another at the fire department connection, which makes it a physical object sitting in a riser room or a stairwell your officers already walk past.
Sometimes, security finds out about an impairment by happenstance. A contractor books the work through facilities, pulls the zone, and mentions it to whoever is standing there. An inspector comes through and trips something on his way out. NFPA 25 has the property owner designate an impairment coordinator for exactly this, and plenty of buildings have never named one, so on a Friday afternoon the call to the command center just doesn't happen.
A clock starts when the zone goes down. The standard wants a fire watch once a system has been out more than 10 cumulative hours in a 24 hour period, and the 2026 edition made fire department notification explicit for planned and emergency work both. If nobody told security, nobody started the watch either.
Adding tags to what officers look for on rounds is a cheap fix. A tag they come across goes into a log at the command center with the location, what it was hanging on, and the date and time. The date and time matter most, since they establish how long the building had been running impaired before anybody noticed.
It doesn't replace anyone else's system and there's no reason to stop using the ticketing queue. It just means security has its own record of what it knew and when it knew it.
Signals
New York hospitals have twelve months to build a workplace violence program
New York S5294B was signed on December 12 2025 and takes effect on the 280th day after that, which lands this month. General hospitals and nursing homes then get twelve months from the effective date to establish a workplace violence prevention program, and the annual safety and security assessments start January 1 2027. The plan has to cover employees, patients, residents, and visitors.
To find out what's required, the statute is pretty direct: Incident reports, employee complaints, facility layout, access points, engineering controls, local crime rates, and the facility's relationships with law enforcement. Whatever the assessment finds has to feed back into the plan through training, security staffing, barriers, lighting, alarms, and communication systems. Employees and union representatives get input, and they get a written summary of the incident reporting procedure along with redacted incident logs and trend analysis.
The staffing requirement is the one that costs money. Emergency departments in counties over 1 million people need security present at all times, and everywhere else the rule is only that security be posted with priority given to the ED. That's a population threshold rather than a volume one, so a busy ED in a smaller county doesn't trigger the continuous post.
New York joins at least 20 states that have put workplace violence prevention obligations on health care employers, covering plans, site assessments, training, and recordkeeping. There is still no federal OSHA standard written specifically for workplace violence, so the operative rules keep arriving from the states one at a time.
Passdown
dictated by Ricky Portezzo, Senior Security Supervisor in Center City, Philadelphia
Riser room on 3 is tagged, watch is running, facilities has it, and the log is in the binder with my name on the first 6 entries.
Mikey put check the valves on the round sheet last month and I'll be honest, I thought it was busy work. 40 years and not once has anybody called down here to tell me a sprinkler was out. I always figured if it mattered, somebody whose job it is would say something. That's facilities. I've got doors and I've got people, I don't have valves.
So Tuesday I'm doing the 0200 and I go in the riser room on 3 because it's on the sheet now, and there's a red tag hanging right there on the valve. Dated the 2nd. I'm standing there like a week later.
Nobody said nothing to nobody, no watch, no notification, no nothing, and I've walked past that door a thousand times in my life and never once looked at what was behind it.
Called Dennis at home, which he loved at 2 in the morning, and he didn't know either. Contractor pulled it for a repair and never came back for it.
Started the watch myself standing right there. Been on it since.
Zone's still down, Dennis is chasing the contractor.
A fire watch nobody logged is a fire watch you can't prove.
SCC Spectrum Security Almanacs. www.gsoc911.com/products
