What Happened in the Reframe Data Breach?
Glucobit, Inc., doing business as Reframe, recently disclosed a data breach that may have exposed sensitive personal information belonging to its users. The company filed a formal notification with the Washington State Attorney General in July 2026. This filing confirmed that an incident occurred involving unauthorized access to data connected to Reframe’s services.
According to the notification, the exact date the breach was discovered has not been publicly disclosed. However, the company moved to notify regulators and affected individuals in July 2026 once it understood the scope of the incident. As a result, many details about how the breach unfolded remain limited to what appears in the official filing.
Because Reframe operates in the health and wellness space, the nature of the exposed information raises particular concern. In response to the discovery, the company appears to have launched an internal review to determine which systems were affected. This kind of investigation typically involves forensic specialists who trace how the intrusion happened and which records were accessed.
At this time, the public record does not specify whether the breach resulted from a ransomware attack, an external hacking attempt, or another form of unauthorized access. Therefore, individuals should rely on official notices from the company for the most accurate account of what occurred. Still, the confirmed filing establishes that real exposure of personal data took place.
Who was affected?
The breach notification does not state a specific number of affected individuals. This means the full scope of the incident has not been publicly disclosed. Nevertheless, the fact that Glucobit filed a formal notice indicates that a meaningful number of people were impacted.
Those affected are likely users of the Reframe platform who submitted personal or health-related information as part of using the service. Because Reframe’s offerings relate to personal wellness tracking, the affected population may include everyday consumers across multiple states. In addition, it is not yet clear whether employees or only customers were involved in this incident.
It also remains unknown whether minors could be among those affected. Given that health-related platforms often serve a broad demographic, the risk profile could vary significantly between users. For this reason, anyone who has used Reframe’s services should treat the notification seriously, even without an exact affected count.
What Information Was Potentially Exposed?
The Washington State Attorney General filing indicates that personal health information was involved in this breach. While the notification does not provide an exhaustive breakdown of every specific data field, health-related platforms typically collect a range of sensitive details tied to a person’s identity and wellbeing.
Based on the nature of the disclosure, the following categories of information may have been exposed:
- Personal health information
- Names associated with health records
- Account or profile details linked to Reframe’s services
- Other identifying information collected during platform use
When health data becomes exposed, the risks extend beyond typical identity theft concerns. For example, exposed health information can be used to commit medical identity fraud, where someone uses stolen details to obtain treatment or prescriptions under another person’s name. This type of fraud can be difficult to detect and may even affect a victim’s medical records.
In addition, personal health details are often considered highly sensitive because they can reveal private aspects of a person’s life. As a result, exposure could lead to targeted phishing attempts that reference specific health conditions to appear more convincing. Because this information cannot simply be changed like a password, the potential for long-term misuse remains a genuine concern for affected individuals.
What is the company doing?
In response to the breach, Glucobit filed the required notification with the Washington State Attorney General. This step reflects the company’s legal obligation to inform regulators once it confirmed unauthorized access to personal data. Filing this notice also set the stage for informing affected individuals directly.
Beyond the regulatory filing, the specific remediation steps taken by the company have not been fully detailed in the public record. However, organizations facing similar incidents typically work to secure affected systems, patch vulnerabilities, and review internal security practices. It is reasonable to expect that Reframe has taken, or is taking, similar measures.
The notification does not confirm whether free credit monitoring or identity protection services are being offered to affected individuals. Therefore, anyone who receives a notice from the company should read it carefully for details about any protective services included. If no such offer appears, affected individuals may still want to consider enrolling in monitoring services on their own.
What Should Affected Individuals Do?
Monitor Your Credit Reports Regularly
Anyone connected to this breach should begin checking their credit reports for unfamiliar activity. This step is important even when Social Security numbers have not been confirmed as exposed, because identity thieves often combine multiple data sources to commit fraud.
You can request free credit reports from the three major bureaus and review them for accounts or inquiries you don’t recognize. In addition, setting up ongoing monitoring can help you catch suspicious activity early, before it causes lasting financial damage.
Stay Alert for Phishing Attempts
Because health information was potentially exposed, affected individuals should watch for phishing emails or messages that reference personal health details. Scammers often use stolen information to make fraudulent messages seem legitimate and trustworthy.
If you receive an unexpected message asking for personal information or payment, avoid clicking links or providing details. Instead, contact the organization directly using a verified phone number or website to confirm whether the message is genuine.
Protect Your Health Records
Given that personal health information may have been involved, affected individuals should review their medical records and insurance statements closely. This helps you spot signs of medical identity fraud, such as unfamiliar treatments or billing charges.
If you notice anything unusual, contact your healthcare provider or insurer right away to dispute the activity. Acting quickly can help limit the damage and prevent incorrect information from becoming part of your permanent medical history.
Consider Consulting a Data Breach Attorney
Because this breach involved sensitive personal health information, affected individuals may want to understand their legal options. A data breach attorney can review the details of your situation and explain whether you may be entitled to compensation.
Many attorneys offer free consultations, so reaching out costs nothing upfront. This step can help you make an informed decision about pursuing a claim while staying aware of any applicable deadlines.
More Information
Official data breach notification report (PDF) from Washington State Attorney General
