United States v. Miller: Third-Party Doctrine and Bank Records

In United States v. Miller, the Supreme Court held 7-2 in 1976 that you have no Fourth Amendment privacy interest in the checks, deposit slips, and statements your bank holds about you, because those documents are the bank’s business records rather than your private papers. That ruling created what is now known as the third-party doctrine: the rule that information you share with a business is no longer constitutionally protected against the government. Nearly 50 years later, the doctrine still governs how federal agents, prosecutors, and grand juries reach into your financial life, though Congress and a later Supreme Court decision have carved out limits around its edges.

What the Court Decided

The case grew out of a federal moonshining investigation. Agents from the Bureau of Alcohol, Tobacco and Firearms served grand jury subpoenas on two Georgia banks where Miller held accounts and obtained checks, deposit slips, and monthly statements without notifying him.1Justia Law. United States v. Miller, 425 U.S. 435 (1976) Miller moved to suppress the records as the product of an illegal search.

Justice Lewis Powell, writing for the majority, rejected the argument on every front. The subpoenaed documents were the banks’ business records. Checks were “negotiable instruments to be used in commercial transactions,” not confidential communications. And every piece of information the government obtained had been “voluntarily conveyed to the banks and exposed to their employees in the ordinary course of business.”1Justia Law. United States v. Miller, 425 U.S. 435 (1976)

The passage that would define decades of Fourth Amendment law came next: “The depositor takes the risk, in revealing his affairs to another, that the information will be conveyed by that person to the Government.” That risk exists, the Court said, “even if the information is revealed on the assumption that it will be used only for a limited purpose and the confidence placed in the third party will not be betrayed.”1Justia Law. United States v. Miller, 425 U.S. 435 (1976)

Because Miller had no legitimate expectation of privacy in records held by his banks, the government did not need a warrant. A subpoena, which requires far less than the probable cause a warrant demands, was enough.

Justice Brennan dissented, arguing it is “impossible to participate in the economic life of contemporary society without maintaining a bank account” and that the totality of a person’s bank records amounts to “a virtual current biography.” Allowing police to obtain those records on request, “without any judicial control,” he warned, “opens the door to a vast and unlimited range of very real abuses of police power.”1Justia Law. United States v. Miller, 425 U.S. 435 (1976) The majority was not persuaded. That language would matter later.

How Miller Became the Third-Party Doctrine

Three years after Miller, the Court applied the same logic to telephone records. In Smith v. Maryland, police used a pen register to capture the numbers a suspect dialed from his home phone. The Court held that installing the device was not a search, because the caller had “voluntarily conveyed numerical information to the telephone company and exposed that information to its equipment in the ordinary course of business” and thereby “assumed the risk that the company would reveal to police the numbers he dialed.”2Justia Law. Smith v. Maryland, 442 U.S. 735 (1979)

The phrasing is almost identical to Miller. Together the two cases established a broad principle: when you share information with a business to get its service, the Fourth Amendment stops protecting that information from the government. Bank records, dialed phone numbers, and by extension a growing range of records held by service providers all fall outside constitutional protection. Investigators can reach them with subpoenas or court orders that do not require probable cause.

What This Means for Your Bank Records

The practical consequence of Miller is that your financial history is far more accessible to the government than most people assume. Under the Bank Secrecy Act, banks must copy every check drawn on the bank and every instrument received for deposit or collection.3Office of the Law Revision Counsel. 12 U.S. Code 1829b – Retention of Records by Insured Depository Institutions Federal regulations require them to keep those records for five years and available within a reasonable period.4eCFR. Nature of Records and Retention Period Because Miller treats those records as the bank’s property rather than yours, investigators can reach back years into your finances with a subpoena rather than by conducting real-time surveillance.

Some of what banks share with the government is affirmatively hidden from you. The Bank Secrecy Act requires banks to file Suspicious Activity Reports when they detect potentially illegal transactions, and federal rules prohibit the bank from telling the customer that a report was filed. A bank that receives a subpoena for SAR-related information must refuse to produce it and notify federal regulators instead.5eCFR. 12 CFR 21.11 – Suspicious Activity Report Records about you can be generated, sent to the government, and kept permanently secret from you.

The Statutory Protection Congress Added

Congress was troubled enough by Miller to pass the Right to Financial Privacy Act (RFPA) in 1978. The RFPA does not overturn Miller‘s constitutional holding, but it imposes procedures federal agencies must follow before obtaining a customer’s bank records.

When a federal agency seeks financial records through an administrative subpoena, judicial subpoena, or formal written request, it must serve notice on the customer on or before the date the request goes to the bank. The notice has to describe the nature of the inquiry with “reasonable specificity” and tell the customer about the right to challenge the disclosure.6Office of the Law Revision Counsel. 12 U.S. Code Ch. 35 – Right to Financial Privacy For search warrants, the government has up to 90 days after execution to mail you a copy.

To fight the disclosure, you have 10 days from service or 14 days from mailing to file a motion to quash a subpoena or an application for an injunction against a formal request. The motion needs a sworn statement explaining why the records are irrelevant or why the government failed to follow the RFPA. Courts must resolve the challenge within seven calendar days of the government’s response.6Office of the Law Revision Counsel. 12 U.S. Code Ch. 35 – Right to Financial Privacy

The exceptions are broad, and worth knowing before you assume the RFPA covers your situation. Grand jury subpoenas bypass the notice requirement entirely. So do requests tied to tax investigations under the Internal Revenue Code, supervisory or regulatory examinations, and Government Accountability Office audits.7Office of the Law Revision Counsel. 12 U.S. Code 3413 – Exceptions Basic account information such as name, address, account number, and account type can be obtained without any notice at all. Grand jury subpoenas were the tool used in Miller itself, so the RFPA would not have changed the outcome of that case.

If a bank or federal agency violates the RFPA, you can sue for $100 in statutory damages regardless of how many records were disclosed, plus actual damages, punitive damages for willful violations, and attorney’s fees. The statute of limitations is three years from the violation or its discovery, whichever is later.6Office of the Law Revision Counsel. 12 U.S. Code Ch. 35 – Right to Financial Privacy

Where the Doctrine Stops: Carpenter and Location Data

For more than 40 years, Miller and Smith stood unchallenged. Then in 2018 the Supreme Court drew a line. In Carpenter v. United States, federal agents obtained 127 days of historical cell-site location information from Timothy Carpenter’s wireless carrier without a warrant. The Court held 5-4 that acquiring the data was a Fourth Amendment search requiring a warrant supported by probable cause.

Chief Justice Roberts wrote that “there is a world of difference between the limited types of personal information addressed in Smith and Miller and the exhaustive chronicle of location information casually collected by wireless carriers today.”8Justia Law. Carpenter v. United States, 585 U.S. ___ (2018) The Court pointed to several features that distinguished cell-site data: it provides encyclopedic tracking of a person’s movements rather than isolated transactions; it is generated automatically by incoming calls, texts, and background connections rather than by any deliberate act; and carrying a cell phone is “indispensable to participation in modern society,” making the supposed choice to share data with the carrier largely illusory. The majority explicitly echoed the “virtual current biography” concern from Justice Brennan’s Miller dissent.

The ruling was deliberately confined. The Court described it as “narrow” and said it did not disturb the application of Smith and Miller to conventional financial records and phone metadata, did not address security cameras or business records that incidentally reveal location, and did not address foreign affairs or national security collection.9Legal Information Institute (LII) / Cornell Law School. Carpenter v. United States For bank records, utility records, and most non-location business data, the third-party doctrine still controls. Carpenter is an exception, not a replacement.

What’s Still Being Fought Over

Lower courts are now testing how far Carpenter‘s reasoning stretches. Two fronts stand out.

Cryptocurrency exchanges look a lot like the Miller facts in a digital setting. The IRS has used John Doe summonses to obtain bulk customer records from exchanges, and litigation is testing whether the third-party doctrine applies to digital financial records the same way it applied to paper checks. Challengers argue the doctrine is outdated and unworkable when applied to cloud-based platforms holding comprehensive transaction histories, and several state attorneys general have urged the Supreme Court to revisit Miller in this context.

Consumer DNA databases raise a sharper question. Law enforcement has searched genetic databases like GEDmatch to identify criminal suspects through familial matching, often without a warrant. Legal scholars argue that Carpenter‘s logic should extend to genetic data, which is both deeply personal and involuntarily shared with biological relatives who never consented to any search.

The pattern is straightforward. The third-party doctrine was built for a world where sharing information with a business meant handing a physical document to a specific person. It now operates in a world where nearly every digital interaction generates records held by someone else, from search queries and email metadata to smart-home logs and biometric data. Miller remains good law for traditional financial records. Its logic is under more pressure than at any point since 1976.