Dubin v. United States
The Supreme Court unanimously threw out a man's aggravated identity theft conviction, ruling that a patient's name appearing on a fraudulent billing form is not enough — the misuse of the identifying information must be the core of the crime, not just a side detail of how billing happens to work.
The decision reins in a federal law that prosecutors had stretched to add mandatory prison time to a wide range of billing fraud cases, and sets a new standard requiring courts to ask whether the fraud was really about someone's identity or just about inflated charges.
“Words can wound, but names and numbers are not guns.”
The majority explaining why the 'use in relation to' language in the firearms statute cannot simply be transplanted into the identity theft context.
How it got here: Dubin was convicted at trial; the District Court denied his post-trial challenge but expressed doubt about the result; the full Fifth Circuit affirmed in a fractured en banc ruling; the Supreme Court agreed to hear the case to resolve a conflict among lower courts.
The Case in Depth
What happened
David Dubin helped run a psychological services company that billed Medicaid for testing as if a fully licensed psychologist had performed it, when in fact a lower-credentialed associate did the work. The total overbilling amounted to $338. Federal prosecutors charged him not only with healthcare fraud but also with "aggravated identity theft" — a separate federal crime carrying a mandatory two-year prison sentence — because the fraudulent bill included the patient's Medicaid reimbursement number.
The question before the Court
Does using a patient's name or account number as a routine part of a fraudulent billing form automatically make the crime "aggravated identity theft," triggering an extra mandatory two-year prison sentence?
The Court's answer
No — a patient's name or account number showing up on a fraudulent bill does not automatically turn billing fraud into aggravated identity theft. The Court held that the federal aggravated identity theft statute is violated only when the misuse of another person's identifying information sits at the core of what makes the underlying offense criminal. If the identifying information is merely an ordinary, incidental part of the billing process, the statute does not apply.
Here, the heart of Dubin's fraud was lying about the qualifications of the employee who performed psychological testing — a misrepresentation about how and by whom services were provided, not about the patient's identity. The patient's Medicaid number was a routine billing detail, not the engine of the fraud. Because the identity was ancillary rather than central to the crime, the mandatory two-year sentence for aggravated identity theft could not stand.
Curious how the Court got there? See the step-by-step legal reasoning →
Why it matters
People accused of billing fraud — in healthcare, contracting, and other industries — will no longer automatically face an extra mandatory two-year federal prison sentence just because another person's name or account number appeared on the fraudulent bill. Courts must now determine whether the identity itself was the vehicle of the crime, which should narrow how often prosecutors can stack this charge on top of ordinary fraud.
What changes now
The Fifth Circuit's judgment is wiped out and the case is sent back to the lower courts for further proceedings. On remand, the courts must also decide a procedural question the Fifth Circuit never resolved: whether Dubin properly preserved his challenges to the §1028A conviction or must clear the higher bar that applies when a legal argument is raised for the first time on appeal. The core holding — that a patient's name being incidental to billing fraud is not enough for aggravated identity theft — is now binding on all lower courts.
What this does not decide
The ruling explicitly does not change how courts apply the similar "use in relation to" language in the federal firearms statute (18 U.S.C. §924(c)). It also does not settle the meaning of the "without lawful authority" element of §1028A(a)(1), which the Court left for another day, and it does not address close cases at the margins of the new "crux" standard.
Concurrences and dissents
Concurrence — Justice Gorsuch
“Truly, the statute fails to provide even rudimentary notice of what it does and does not criminalize. We have a term for laws like that. We call them vague.”Justice Gorsuch arguing the aggravated identity theft statute is so unclear it may be unconstitutionally vague, beyond just ambiguous.
Justice Gorsuch agreed that the Government's reading was far too broad and that Dubin's conviction cannot stand, but he declined to join the majority's 'crux of the criminality' test. In his view, the test is itself too vague to give ordinary people fair notice of what the law prohibits — a constitutional requirement. He argued the statute may be unconstitutionally vague and warned that lower courts will struggle to apply the majority's standard consistently. He suggested only Congress can truly fix the problem by rewriting the law.
How the Court got there
The legal reasoning, step by step
- The case turned on two elastic statutory terms: whether Dubin 'used' a patient's means of identification 'in relation to' healthcare fraud under §1028A(a)(1). Both terms are highly context-dependent — 'use' carries many possible meanings, and 'in relation to' can expand almost without limit if read in isolation — so the Court needed to look beyond the words themselves to the surrounding statutory scheme.
- The statute's title, 'Aggravated identity theft,' provided an important textual clue. Titles are legitimate tools for resolving statutory ambiguity, and here the title was especially reliable: §1028A is a focused, standalone provision (not a sprawling list), and its title lines up with what the text's own nouns and verbs suggest. Congress also deliberately separated §1028A (identity theft) from neighboring §1028 (fraud involving identification documents broadly), signaling a narrower focus.
- The Court applied the interpretive principle 'noscitur a sociis' — meaning a word takes on meaning from the company it keeps. 'Uses' appeared alongside 'transfers' and 'possesses,' both of which plainly connote identity theft: unlawfully taking and moving someone else's identifying information. Reading 'uses' consistently with those neighbors, it too requires that the identifying information play a central, deceptive role — specifically, that the fraud concern who someone is, not just how or when a service was performed.
- The mandatory sentencing structure further undermined the Government's sweeping reading. Section 1028A(a)(1) stacks a 2-year mandatory prison term on top of underlying offenses that carry no mandatory minimum at all. If the Government were right, this severe enhancement would trigger automatically in virtually any fraud touching a name or account number — including routine overbilling — collapsing any real distinction between the aggravated crime Congress singled out for extra punishment and ordinary fraud.
- The Court's traditional caution about reading criminal statutes too broadly reinforced the narrower interpretation. When a proposed reading would sweep in the lawyer who rounds up billable hours, the waiter who substitutes one cut of meat for another, or the contractor who adds $10 to the price of paint, the sheer implausibility of those results weighs strongly against adopting that reading — and the Court refused to rely on prosecutorial discretion to cabin such an open-ended law.
- Applying the 'crux of the criminality' standard to Dubin's case: his fraud was about misrepresenting the credentials of the employee who performed the testing, not about the patient's identity. The patient's Medicaid number was a standard part of the billing paperwork. Because the patient's identity was not what made the billing fraudulent, Dubin did not commit aggravated identity theft within the meaning of §1028A(a)(1).
Doctrinal impact
Cases affected by this decision
Reaffirms Flores-Figueroa v. United States (556 U. S. 646)
The Court built directly on Flores-Figueroa's reading of §1028A as a focused identity-theft statute, not a broad fraud provision.