Are Smart Glasses Allowed in Hospitals?

A flat editorial illustration on a cream background. A thick red rounded rectangle frames a pale teal panel; inside it a
AI-generated editorial illustration. Not a documentary image.

HIPAA binds the doctor wearing them, not the visitor filming

In September 2025 a cybersecurity firm published a post that left no room for a second reading. Its headline was Hospitals Should Ban Meta Ray-Ban Smart Glasses, and by early 2026 the advisories had multiplied around it. A healthcare consultancy told hospitals to prohibit the glasses for patients and visitors outright and to post signage at the entrance. An HR firm laid out how a healthcare employer could bar staff from wearing them in any patient-care area. Each pointed at the same three-letter reason: HIPAA.

Then there is what the one large health system with a written rule actually decided. UW Medicine did not ban the devices. Its published wearable-technology guidance permits smart glasses for telehealth and medical education: on conditions, but permitted.

That gap between "ban them" and "manage them" is the story, and it turns on a point almost none of the alarmed coverage stops to make: HIPAA does not reach the person most readers picture when they imagine camera glasses in a waiting room. It has nothing to say to the visitor filming in the corridor. It binds the hospital.

The law reaches the hospital, not the person filming

HIPAA is not a general privacy law that follows a camera around. It applies to a defined and fairly short list of parties. Under the federal definition at 45 CFR 160.103, a "covered entity" is a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form" for a covered transaction, and, by extension, the business associates those entities hire. A patient is not on that list. Neither is a visitor.

Sara Jodka, writing in Dickinson Wright's health law blog in June 2026, puts it flatly: "HIPAA regulates covered entities and their business associates; it does not regulate patients or ordinary visitors." A patient who records their own appointment on their own glasses is not breaching HIPAA, because the law was never pointed at them. A relative filming a hallway is outside it too. What can reach either of them is a different body of law entirely — state recording-consent statutes, which for the audio a pair of glasses captures by default is the harsher half. In five states a secret recording of a private conversation is a felony, not the civil matter the roundups imply, and that exposure sits on the wearer whether or not a hospital is anywhere nearby.

The exposure that genuinely is HIPAA's runs the other way, toward the staff. Tim Bajarin, writing in Forbes in February 2026, drew the line in one sentence: "A nurse wearing smart glasses with live recording brings immediate compliance risks." That is the sentence the "ban them" headlines are really about, even when they are illustrated with a picture of a visitor. The device that creates a HIPAA problem is the one on a clinician's face, and the bill for it lands on the organisation, not only on the person wearing it.

A face, a wristband, a monitor caught in the background

The reason a clinician's glasses are the problem is that a hospital is wall-to-wall protected health information, and the camera does not choose what it sees.

Protected health information, again under 45 CFR 160.103, is any individually identifiable health information: information that relates to someone's care or the payment for it and that identifies them, or could. What counts as identifying is broader than a name. When the rules list the identifiers that have to be stripped to call data de-identified, at 45 CFR 164.514(b)(2), the list runs to eighteen items and two of them are exactly what a camera collects without trying: "Biometric identifiers, including finger and voice prints," and "Full face photographic images and any comparable images." A face is an identifier. A voice is an identifier. A wristband with a name on it is one too.

So a device that, in Jodka's words, "incidentally captures a patient's face, a name on a chart or wristband, a monitor or computer screen displaying results, or a conversation about diagnosis or treatment has captured PHI." It does not matter that the wearer was recording something else, or nothing in particular. The frame swept it up.

HIPAA does leave room for the incidental. A covered entity is permitted to make disclosures that are "incident to" a legitimate use, under 45 CFR 164.502(a)(1)(iii), but only where it has applied reasonable safeguards and honoured the rule's "minimum necessary" standard at 164.502(b). That is the door an always-on camera walks straight through and cannot close behind it. A device recording continuously is capturing the maximum available, not the minimum necessary, and there is no safeguard on what a passing frame happens to hold.

The glasses differ from every recorder a hospital already knew how to police in the one respect that matters here. When someone raises a phone, the room knows. LBMC's Garrett Zickgraf, author of that blunt September headline, put the distinction precisely: unlike smartphones or cameras, "which have clear screens and visible user intent, these glasses do not provide obvious cues to indicate they are recording." The HR advisory from CEDR Solutions made the same point about staff — their ordinary appearance "can also make it harder for patients, coworkers, and managers to know whether recording is taking place." The risk a hospital is actually managing, then, is not a rogue clinician. It is a conscientious one whose device is quietly collecting other people's PHI that nobody consented to and nobody in the room can see being collected.

The hospital that wrote it down chose rules over a ban

Against all of that, it would be easy to assume every serious health system has slammed the door. The published record says otherwise, and it is thin, which is itself worth saying.

UW Medicine's wearable-technology guidance permits the devices for telehealth and medical education "so long as they are HIPAA compliant," and then fences the permission with conditions that read as a direct answer to the risks above. Patients and others present "must be informed at the onset of the encounter since the actual recording may not be apparent": the invisibility problem, met head-on. Recordings "must be limited to the operation, procedure or wound itself": the minimum-necessary rule, made concrete. The captured PHI "must remain within UW Medicine," and only "the minimum amount of PHI necessary" may be used. Jodka's blog holds that structure up as a model for exactly this situation: vet the technology, inform the patient, limit the capture, keep the data inside, minimise. (UW Medicine's page blocks automated readers; its wording here is corroborated by the Dickinson Wright analysis, which cites it as a model, and the access limit is noted in the sources below.)

The distance between that and "hospitals should ban" is the distance between advocacy and administration. The compliance firms are recommending the safest possible posture, which is their job. UW Medicine wrote a policy it intends to run, which is a harder thing, and it decided the device could be governed rather than expelled. Both can be defensible; they are not the same act, and a reader who only met the first would think the second was impossible.

An employer barring the glasses from staff is a real option inside all this — but even that is not the clean move it looks like. As the Disney security guard's pending ADA lawsuit shows, whether an employer can simply ban smart glasses at work gets complicated the moment the glasses are prescribed, and a blanket rule is the version most exposed to challenge.

What no regulator has actually said

The quiet fact underneath every advisory is that the federal government has not weighed in. None of the guidance found for this piece points to any HHS or Office for Civil Rights document, letter or enforcement action that addresses smart glasses specifically. The consultancies reach instead for general compliance-program guidance and stretch the twenty-five-year-old Privacy Rule over a device its drafters never imagined.

That leaves the question a reader types — are smart glasses allowed in hospitals — with an honest answer in three parts. There is no law that names them. The general rule they fall under, HIPAA, reaches the hospital and its staff and not the patient or visitor holding the camera. And the institutional policies that would fill the gap mostly do not exist yet: the one on the public record permits under conditions rather than banning. It is the same unwritten space this cluster found on the visitor's side, where the cinema settled its recording rule in 2014 and the hospital is only now being urged to write one at all.

Which means the person most likely to create a HIPAA problem in a hospital tomorrow is not the one the ban headlines picture. It is a member of staff, doing their job, wearing a camera nobody around them can tell is on.

Sources and verification

No HHS or Office for Civil Rights guidance or enforcement action specific to smart glasses was located, and none is asserted here. No named health system was found to have publicly banned the devices; the published policy on record permits them under conditions. No penalty figure is stated because none was tied to a smart-glasses case in a source that was opened.