Amgen disclosed on July 31, 2026 that hackers stole company and patient data from cloud storage environments run by third-party providers, a reminder that healthcare data risk now lives as much in vendor cloud environments as inside hospital and pharmaceutical networks themselves.
In an 8-K filing with the SEC, Amgen said it “identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers” in July 2026, and confirmed “some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated.” Amgen determined on July 29 that the incident was material under SEC disclosure rules based on the volume and sensitivity of the affected files. The filing states the company has not identified any impact to its products, manufacturing operations, or financial reporting systems.
Why it matters: Amgen has not disclosed which cloud providers were involved, how the environments were compromised, or how many patients are affected, leaving peer security teams little technical detail to act on. The filing does confirm the shape of the exposure, proprietary business data and protected health information sitting in cloud environments outside Amgen’s own perimeter, a pattern recurring across healthcare and life sciences as more clinical data moves to third-party cloud infrastructure.
The original insight here is less about Amgen and more about where accountability sits. Amgen says its products and manufacturing systems were unaffected, meaning the exposure ran through data storage relationships, not operational technology. That distinction matters for the security leader building third-party risk programs: cloud storage vendors handling regulated health data warrant the same access reviews and incident-notification terms as systems on the corporate network. It is the same lesson from DentaQuest’s disclosure that a single compromised data environment could expose tens of millions of patient records, arriving here from the cloud-storage side rather than a direct application breach.
Amgen says it has engaged forensic experts and will issue required notifications, including to affected patients, once its investigation concludes. Security teams with similar cloud storage relationships should confirm which vendors hold protected health or proprietary data, and whether contract notification timelines match a material SEC disclosure.
Source: SEC EDGAR