Amgen Says Hackers Stole Patient Health Information From Third-Party Cloud Systems
Amgen disclosed that hackers stole company data and patient health information from cloud-storage systems operated by third-party providers.
Why it matters: The breach shows how external cloud providers can expose regulated healthcare data even when core company systems remain separate.
Biotechnology company Amgen has disclosed that hackers stole company data and patient health information during a cybersecurity incident involving cloud-storage systems operated by third-party providers.
Amgen determined on July 29 that the incident was material after evaluating the number of affected files and the potential sensitivity of their contents.
The company activated its cybersecurity-response plan, implemented containment measures and hired independent forensic experts to investigate the breach.
Amgen has not publicly identified the affected cloud providers, the attackers or the initial-access method. It has also not disclosed how many patients may be affected.
The incident highlights the importance of third-party cloud risk in healthcare and pharmaceutical operations. Sensitive information may be distributed across software vendors, research partners, data processors and external storage platforms.
Healthcare information is especially valuable to attackers because it can contain identity data, insurance information, treatment histories and other records that cannot easily be replaced or reset. Organizations need inventories of where sensitive records live, provider access controls, encryption requirements and rapid incident-notification clauses.