Amgen Confirms Patient PHI Theft From Cloud Systems: Five Checks for Healthcare Organizations
A major biotechnology company has confirmed that protected health information was taken from data stored in third-party cloud environments. The incident is a timely reminder for healthcare organizations of every size: moving data to the cloud does not move away your responsibility to understand where sensitive information lives, who can access it, and how suspicious activity will be detected and handled.
What Amgen confirmed
In a Form 8-K filed with the U.S. Securities and Exchange Commission on July 31, 2026, Amgen said it identified unauthorized activity in July involving data stored in cloud environments hosted by third-party cloud service providers.
Amgen reported that data exfiltrated from those environments included proprietary information, patient protected health information, and other data. The company activated its cybersecurity response plan, implemented containment measures, and engaged independent forensic experts. It determined the incident was material on July 29 based on the apparent volume of affected files and the potential sensitivity of the information.
The investigation remains ongoing. At the time of the filing, Amgen had not identified an impact on its products, manufacturing operations, financial reporting systems, or ability to meet patient needs.
What has not been disclosed
Several important details were still unknown or unavailable in Amgen’s filing, including:
• The identity or motive of the attacker.
• The initial access method.
• The cloud provider or providers involved.
• The number or location of affected patients.
• The specific PHI fields that were taken.
• The full extent of any affected intellectual property or research and development information.
Those gaps matter. They also mean healthcare leaders should avoid turning this disclosure into speculation about a particular vendor, attack technique, or number of victims.
The larger lesson: cloud security is a shared responsibility
Cloud platforms can provide strong security capabilities, but those capabilities still have to be configured, monitored, and governed. HHS guidance says healthcare organizations using cloud services for electronic PHI should understand the cloud environment, conduct their own risk analysis, establish appropriate risk-management policies, and maintain appropriate business associate agreements.
For a small medical office, dental practice, hospice provider, home-health agency, or senior-living organization, the practical question is not simply, “Is our data in the cloud?” The better questions are: “Which cloud systems contain PHI? Who can get into them? What evidence would show us that something went wrong? And what would we do next?”
Five checks healthcare organizations should make now
1. Locate PHI across every cloud platform
Create a current inventory of systems that store, process, or transmit patient information. Include the EHR, email, file-sharing platforms, backup services, billing systems, patient portals, collaboration tools, and vendor-managed applications. Assign an owner to each system and document what information it contains.
2. Review identities and privileged access
Confirm that multifactor authentication is enforced, especially for administrators and remote access. Remove stale accounts, separate daily-use and administrative identities, and review vendor and contractor access. Access should match each person’s actual role—not simply remain in place because it was granted years ago.
3. Confirm that useful logging is enabled
Logs should help answer who signed in, from where, what they accessed, and what changed. Verify that important audit logs are enabled, retained long enough to support an investigation, and reviewed through alerts or routine monitoring. A log that exists but is never checked provides limited protection.
4. Revisit vendor agreements and escalation contacts
Confirm which vendors are business associates, where the applicable agreements are stored, and who must be contacted during an incident. Review notification expectations, security responsibilities, data return or destruction terms, backup and recovery commitments, and the process for obtaining relevant records during an investigation.
5. Practice the first day of a cloud incident
Document the first actions your team would take if cloud data might have been accessed: preserve evidence, disable or restrict affected access, rotate credentials where appropriate, contact the right internal and external parties, maintain patient-care workflows, and begin the required legal and regulatory assessment. Test the plan before an emergency exposes missing contacts or unclear authority.
What this means for your practice
Amgen’s disclosure does not prove that every cloud system is unsafe. It shows why “the vendor handles security” is not a complete operating model. Healthcare organizations need visibility into their own users, data, configurations, contracts, logs, and response procedures—even when a third party hosts the technology.
A practical review does not have to begin with a massive project. Start with the systems holding the most sensitive information and supporting the most important patient-care processes. Identify the highest-risk gaps, assign owners, and build a realistic improvement plan.
A sensible next step
Vault Technologies helps healthcare organizations understand where technology risk may affect privacy, operations, and care continuity. A Technology Health Assessment can help establish a clear starting point for reviewing access, cloud governance, documentation, vendor dependencies, and recovery readiness.
Ready to see where your organization stands? Start your Technology Health Assessment or contact Vault Technologies to discuss your environment.









