The Healthcare Industry Is Coming for Your Face
11 hours ago
- Headway, a mental health billing service, now requires patients to submit a government ID and a live facial scan via third-party vendor Persona, with no opt-out.
- The stated purpose of fraud prevention is undermined by data showing most healthcare fraud is provider-side, and patient deepfake threats in telehealth are unproven.
- Biometric data is irreversible; unlike a credit card number, a face cannot be changed if breached, and deletion during collection does not prevent exposure during transmission.
- Everyday uses like Face ID (on-device) normalize facial scans, but healthcare scans involve storing sensitive data on private servers with weak protections.
- Headway's customer support relies on a bot that provides incorrect information and refuses to escalate unless users quote the company's own email.
- Current U.S. biometric laws are patchy: Illinois' BIPA has a healthcare exemption, Texas' CUBI lacks private enforcement, and Washington's new law is limited to one state.
- A better approach would include clear policies, real opt-out alternatives, human support, and federal regulations with a private right of action.