Health Services LLC, d/b/a Miracle Ear, has experienced a major data breach. On or around Jan. 28, 2025, Miracle Ear became aware of suspicious activity on its network. An investigation determined that cybercriminals accessed the Miracle Ear network from on or about Jan. 2, 2025 to on or about Jan. 28, 2025. The unauthorized actors had access to and possibly obtained files containing consumer information.
The cybersecurity incident compromised both personally identifiable information (PII) and protected health information (PHI) of individuals involved or who have done business with Miracle Ear. Exposed information includes names, contact information, dates of birth, Social Security numbers, driver's license numbers, patient IDs, medical treatment or diagnosis, and health insurance information, including policy numbers, subscriber ID numbers, claims history and appeal records.
The data breach is considered high risk for impacted consumers because the exposure of both PII and PHI increases the risk of identity theft, medical identity theft and fraud. Health Services, LLC published a Notice of Data Security Incident on its website on March 31, 2025.
Miracle Ear also disclosed the data breach to the Montana and Washington Attorney Generals' offices on Aug. 12, 2025. The data breach impacted 11,088 Washington residents and 2,206 in Montana.
The total number of impacted individuals has not been released but is believed to be higher, as Miracle Ear and its franchisees operate over 1,600 locations across the United States.
In addition to required state and federal disclosures, Health Services LLC is notifying impacted individuals by mail. The organization has also set up a dedicated response line at 800-232-3154, Monday through Friday, 7 a.m. to 4 p.m. Mountain Time.
If you receive a data breach notice from Health Services LLC or Miracle Ear about this breach, you may want to:
For more information about the company, visit the Miracle Ear website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.