Can Healthcare Employers Ban Meta Smart Glasses at Work?

8 MIN READ

Quick answer: Yes. Healthcare employers can generally prohibit employees from wearing Ray-Ban Meta glasses, smart glasses, and other recording-capable wearable devices while working, especially in patient-care and confidential areas.

These devices can create serious risks involving HIPAA compliance, patient privacy, protected health information (PHI), cybersecurity, workplace confidentiality, and unauthorized recording. However, the policy should be carefully written to account for disability accommodations and legally protected employee activity.

Question: It was brought to my attention that an employee who wears Meta glasses to the office recorded themselves treating a patient and uploaded the video to social media. I do not currently have any restrictions regarding Meta glasses in the office, but this situation makes me think I should. Can I prohibit employees from wearing them while working? How should I address the video that is now public? As far as I know, the patient did not consent to being recorded.

Prefer to watch? Check out our video on the topic below.

Can You Prohibit Employees From Wearing Meta Glasses?

The legal side: Yes. Healthcare practices can generally prohibit employees from wearing Meta smart glasses and other recording-capable wearable devices while performing their job duties.

While Meta glasses are one of the newest technologies entering the workplace, the legal and privacy principles involved are not new. Whether an employee uses smart glasses, a body camera, smartphone, tablet, smartwatch, or another recording device, healthcare employers remain responsible for protecting patient privacy and maintaining HIPAA compliance.

That means practices may establish reasonable rules restricting devices that can photograph, record, livestream, store, or transmit information from patient-care and confidential areas.

Even if your employee handbook does not specifically use the term “Meta glasses,” existing policies concerning patient confidentiality, photography, personal recording devices, social media, and PHI may apply. However, relying on general language leaves room for confusion. A carefully written wearable-technology policy gives employees clearer notice and makes enforcement more consistent.

Why Smart Glasses Create HIPAA and Privacy Risks

Meta glasses and similar devices can capture audio, video, and photographs from the employee’s point of view. Their appearance can also make it harder for patients, coworkers, and managers to know whether recording is taking place.

A recording could reveal:

  • A patient’s face, voice, name, or medical condition
  • Treatment being provided
  • Conversations between patients and staff
  • Information displayed on computer screens
  • Medical or billing documents
  • Other patients or employees in the background
  • Confidential workplace or business information

Recording or publicly sharing identifiable patient information without proper authorization may be an impermissible use or disclosure of PHI. The practice should immediately begin its HIPAA incident-response process and determine whether a breach occurred.

Under the HIPAA Breach Notification Rule, an impermissible use or disclosure of unsecured PHI is generally presumed to be a breach unless the practice documents, through the required risk assessment, that there is a low probability the PHI was compromised. Review the HHS breach-notification guidance.

State privacy, audio-recording, and consent laws may create additional obligations. A practice should not rely on HIPAA as its only consideration.

Can a Smart-Glasses Ban Be Too Broad?

Yes. Healthcare employers have strong reasons to restrict recording-capable devices, but the policy still needs to be written carefully.

An absolute rule prohibiting every form of workplace recording, regardless of the circumstances, may interfere with employees’ rights to discuss or document working conditions or engage in other legally protected concerted activity. The National Labor Relations Act protects many employees when they act together to address wages, safety, and other workplace concerns.

The policy should focus on legitimate business needs, including:

  • Protecting patients and PHI
  • Preventing recordings in treatment and confidential areas
  • Protecting cybersecurity and data security
  • Maintaining workplace safety
  • Preventing the disclosure of confidential information
  • Preserving patient trust and professional standards

The policy should also preserve legally protected employee activity.

There may be a separate issue if an employee says smart glasses are needed because of a disability or visual impairment. That statement may trigger an accommodation discussion under applicable disability laws. The employer does not necessarily have to permit recording-capable glasses in patient-care areas, but it may need to consider whether disabling the recording features, using ordinary prescription glasses, or providing another effective accommodation would address the employee’s needs.

What Should a Smart-Glasses Workplace Policy Cover?

A well-written policy should do more than name one brand or device. Technology will continue to change, and a policy limited to Meta glasses could quickly become outdated.

The policy should:

  • If not already broad enough, define smart glasses, wearable cameras, and recording-capable devices (If you’re a CEDR Member, your policy is already broad enough)
  • Prohibit unauthorized photography, audio recording, video recording, live-streaming, and transmission
  • Address patient-care areas, records, screens, conversations, and other sources of PHI
  • Prohibit uploading workplace recordings to personal accounts, social media, cloud-storage services, or AI platforms
  • Explain whether devices must be removed, powered off, or stored during working time
  • Establish a process for approving legitimate business uses
  • Explain how employees should report a suspected unauthorized recording
  • Direct employees to request an accommodation if a device is needed because of a disability
  • Preserve legally protected employee activity
  • Explain that violations may result in corrective action, up to and including termination

The policy should also work together with the practice’s confidentiality, HIPAA, social media, electronic-device, photography, and corrective-action policies.

Learn why healthcare practices need employee handbooks built around their actual workplace risks.

What Should You Do if an Employee Records a Patient?

An employee recording a patient and posting the video publicly should be treated as a serious incident, especially if the recording occurred without the patient’s properly documented authorization or the practice’s knowledge.

The practice should:

  1. Preserve the evidence. Capture screenshots, URLs, dates, account information, comments, view counts, and other available information before the post is removed.
  2. Stop any continued recording or disclosure. Direct the employee to stop recording and stop sharing the content.
  3. Require removal of the content. After preserving the evidence, direct the employee to remove the video from every platform, account, or location where it was uploaded.
  4. Identify where the recording was shared. Require the employee to identify every platform, account, person, or group that received the recording.
  5. Determine what was captured. Identify the patient or patients involved and the PHI, conversations, screens, records, employees, or other confidential information visible or audible in the recording.
  6. Notify the appropriate people. Immediately involve the practice’s Privacy Officer, Security Officer, HIPAA advisor, and legal counsel as appropriate.
  7. Begin the HIPAA assessment. Evaluate whether an impermissible use or disclosure occurred and complete the required breach risk assessment.
  8. Contain the disclosure. Contact hosting platforms or recipients when additional removal or containment efforts are needed.
  9. Determine notification obligations. Based on the assessment, determine whether the patient, HHS, media, state authorities, or others must be notified.
  10. Address the employment issue. Investigate the employee’s conduct and determine the appropriate corrective action.
  11. Update policies and training. Correct any gaps in the practice’s policies, HIPAA procedures, and employee training.

Removing the post quickly is important, but it should not happen before the practice preserves the evidence it needs for its investigation and HIPAA assessment.

How Should You Address the Employee?

The human side: This should not be treated as a casual coaching conversation.

Meet with the employee privately and explain that the practice has learned that a patient interaction may have been recorded and shared publicly. Make clear that patient privacy is one of the organization’s highest priorities and that the practice is conducting a formal investigation.

The investigation should determine:

  • What the employee recorded
  • Whether the employee knew recording was taking place
  • Why the employee made the recording
  • Whether the patient or anyone else was asked for permission
  • Where the recording was stored, posted, or sent
  • Who may have viewed or received it
  • Whether the employee has made other workplace recordings
  • Whether anyone else participated in or knew about the conduct
  • Which policies and training requirements apply

Even if the patient verbally agreed to be recorded, that does not resolve the problem. The practice would need to determine whether there was a valid, properly documented authorization covering the recording and its intended use, storage, and disclosure.

An employee cannot independently obtain a patient’s permission and then decide to record or publish patient content outside the practice’s authorization process.

What Corrective Action Is Appropriate?

Once the investigation is complete, determine the appropriate response based on:

  • The facts established by the investigation
  • What information was recorded and disclosed
  • Whether the conduct was intentional
  • The employee’s explanation
  • The practice’s existing policies and training
  • The employee’s position and privacy responsibilities
  • The extent of the disclosure
  • Whether the employee cooperated with containment efforts
  • How comparable violations have been handled
  • Applicable employment laws and contractual requirements

Depending on the circumstances, corrective action could range from a final written warning to termination of employment.

Deliberately recording a patient and posting the video publicly without authorization may support termination. However, the practice should first preserve the evidence, complete a reasonable investigation, review policy consistency, and consult its HR advisor before making the final decision.

Prevent the Next Unauthorized Recording

Meta glasses are not the last recording-capable device healthcare employers will encounter. Policies written around a single product will eventually become outdated.

Healthcare practices should maintain broader policies addressing:

  • Wearable recording technology
  • Personal electronic devices
  • Photography, video, and audio recording
  • Social media
  • Patient authorization
  • Confidential and proprietary information
  • PHI
  • Cybersecurity
  • Disability accommodations
  • Corrective action

Employees should also receive training explaining that a patient’s apparent willingness to be photographed or recorded does not give an employee permission to create or publish patient content or to record them. Additional steps must be taken.

Read CEDR’s additional guidance on workplace boundaries for wearable technology.

An Employee Recording Can Become Several Problems at Once

An employee recording a patient can become a HIPAA, policy, corrective-action, and public-relations issue at the same time.

CEDR members can contact an HR expert for help coordinating the employment response while the practice works with its Privacy Officer, HIPAA advisor, or legal counsel to complete the privacy assessment.

Not yet a member? CEDR provides customized healthcare employee handbooks, HR guidance, and on-demand HIPAA training to help practices prevent and respond to problems like this.

Frequently Asked Questions

Can an employer ban Meta glasses at work?

Yes. Healthcare employers can generally prohibit Meta glasses and other recording-capable wearable devices while employees are working, particularly in patient-care, treatment, records, and confidential areas. The policy should be based on legitimate privacy, security, safety, and operational concerns and should account for accommodation obligations and legally protected employee activity.

Is recording a patient without consent a HIPAA violation?

Recording or publicly sharing identifiable patient information without proper authorization may constitute an impermissible use or disclosure of PHI. The practice should immediately begin its HIPAA incident-response process.

An impermissible use or disclosure of unsecured PHI is generally presumed to be a breach unless the practice completes the required risk assessment and documents a low probability that the PHI was compromised.

Does a patient’s verbal consent allow an employee to post a recording?

Not necessarily. The practice must control the authorization process and determine the specific conditions governing the recording, its purpose, use, storage, and disclosure. An employee cannot independently obtain permission and decide to record or publish patient content.

Should healthcare practices have a smart-glasses policy?

Yes. Employee handbooks should address smart glasses, wearable cameras, personal recording devices, photography, video, audio recording, social media, confidential information, and PHI. Policies should cover categories of technology rather than only one brand.

Are Meta glasses considered recording devices?

Yes. Ray-Ban Meta glasses and similar smart glasses can capture photographs, video, and audio. Healthcare employers should treat them as recording-capable devices when developing workplace policies.

What if an employee needs smart glasses because of a disability?

The employer may need to begin an accommodation discussion. That does not automatically mean recording-capable glasses must be permitted in patient-care areas. The practice should consider whether recording functions can be disabled or whether another effective accommodation would protect patient privacy while meeting the employee’s needs.

Should the employee be fired for recording a patient?

Possibly. Deliberately recording and publicly posting identifiable patient information without authorization is extremely serious and may support termination. The employer should first preserve evidence, investigate the incident, review the employee’s explanation and applicable policies, evaluate consistency with previous decisions, and consult an HR advisor or employment counsel.

testimonial-form-image

Friendly Disclaimer: This information is general in nature and is not intended to provide legal advice or replace individual guidance about a specific issue with an attorney or HR expert. The information on this page is general human resources guidance based on applicable local, state, and/or federal U.S. employment law that is believed to be current as of the date of publication. Note that CEDR is not a law firm, and as the law is always changing, you should consult with a qualified attorney or HR expert who is familiar with all of the facts of your situation before making a decision about any human resources or employment law matter.

Related reading from the HR basecamp blog

A Blog Written by CEDR, written by HR Experts to help you run your practice.

View all posts

No Tax on Overtime? What Employers Need to Know (OBBBA FAQ)

Mar. 25, 2026

Did overtime become tax-free? No. The law created a federal income tax deduction for the premium portion of qualifying overtime...

I-9 Readiness for 2025: How to Prepare Your Business For a Visit From ICE

Feb. 5, 2025

Employers have always needed to be vigilant about complying with immigration laws, most especially with federal I-9 forms and E-Verify...

Excessive Unpaid Time Off, Bathroom Breaks, and Cell Phone Use

Jul. 1, 2024

You can generally require that an employee use their paid vacation time toward any time off they take.