Health

Amgen says hackers stole patient data in cloud breach

Amgen said hackers took company data and patient health information from cloud systems run by third-party providers, raising the risk of identity, medical and insurance exposure.

Marcus Williams··2 min read
Published
Listen to this article0:00 min
Share this article:
Amgen says hackers stole patient data in cloud breach
Source: pexels.com

Amgen disclosed that it had identified unauthorized activity in cloud environments hosted by third-party cloud service providers and later learned that some data, including patient information, had been stolen. The filing, dated July 29, said the company activated its cybersecurity response plan, contained the intrusion and brought in independent forensic experts as it assessed what was taken.

The breach is especially sensitive because patient health information can reveal identities, diagnoses, treatment histories and insurance-related details. For anyone tied to Amgen’s systems or products, the immediate next step is to watch for breach notices, review medical and insurance statements for unfamiliar activity and be alert to follow-up mail or email that could explain whether personal data was included.

AI-generated illustration
AI-generated illustration

Amgen made the disclosure as healthcare and life sciences companies continue to draw hackers because they store large, valuable datasets and rely on a web of vendors and third-party providers. Reuters said the incident made Amgen the latest healthcare firm to disclose a breach, underscoring how cloud storage and outsourced technology can widen the attack surface even for large drugmakers with established security teams.

The company is based in California and develops and manufactures medicines for serious illnesses including cancer, cardiovascular disease, inflammation and rare diseases, making the exposure of patient data a problem that reaches beyond corporate systems. If the stolen material included names, contact information or treatment records, the fallout could stretch into notification duties, regulatory scrutiny, remediation costs and possible litigation that could last for months or longer.

Amgen has faced cyber reporting obligations before. Amgen investor materials show the company filed a separate cybersecurity-related Form 8-K in April 2020, a reminder that security events can recur and that public companies often have to disclose them to investors when they meet materiality thresholds.

The disclosure also landed against a wider rise in cyberattacks on U.S. companies. Reuters reported on July 27 that attacks were increasing across corporate America, and the Amgen case fits that pattern by showing how a single breach can cut across privacy, compliance, patient trust and business continuity at once.

This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.

Did this article answer your question?

Discussion

More in Health