Amgen Confirms Patient PHI Theft From Cloud Systems: Five Checks for Healthcare Organizations

michael • August 3, 2026

Share this article

A major biotechnology company has confirmed that protected health information was taken from data stored in third-party cloud environments. The incident is a timely reminder for healthcare organizations of every size: moving data to the cloud does not move away your responsibility to understand where sensitive information lives, who can access it, and how suspicious activity will be detected and handled.


What Amgen confirmed


In a Form 8-K filed with the U.S. Securities and Exchange Commission on July 31, 2026, Amgen said it identified unauthorized activity in July involving data stored in cloud environments hosted by third-party cloud service providers.


Amgen reported that data exfiltrated from those environments included proprietary information, patient protected health information, and other data. The company activated its cybersecurity response plan, implemented containment measures, and engaged independent forensic experts. It determined the incident was material on July 29 based on the apparent volume of affected files and the potential sensitivity of the information.


The investigation remains ongoing. At the time of the filing, Amgen had not identified an impact on its products, manufacturing operations, financial reporting systems, or ability to meet patient needs.


What has not been disclosed


Several important details were still unknown or unavailable in Amgen’s filing, including:


• The identity or motive of the attacker.
• The initial access method.
• The cloud provider or providers involved.
• The number or location of affected patients.
• The specific PHI fields that were taken.
• The full extent of any affected intellectual property or research and development information.


Those gaps matter. They also mean healthcare leaders should avoid turning this disclosure into speculation about a particular vendor, attack technique, or number of victims.


The larger lesson: cloud security is a shared responsibility


Cloud platforms can provide strong security capabilities, but those capabilities still have to be configured, monitored, and governed. HHS guidance says healthcare organizations using cloud services for electronic PHI should understand the cloud environment, conduct their own risk analysis, establish appropriate risk-management policies, and maintain appropriate business associate agreements.


For a small medical office, dental practice, hospice provider, home-health agency, or senior-living organization, the practical question is not simply, “Is our data in the cloud?” The better questions are: “Which cloud systems contain PHI? Who can get into them? What evidence would show us that something went wrong? And what would we do next?”


Five checks healthcare organizations should make now


1. Locate PHI across every cloud platform


Create a current inventory of systems that store, process, or transmit patient information. Include the EHR, email, file-sharing platforms, backup services, billing systems, patient portals, collaboration tools, and vendor-managed applications. Assign an owner to each system and document what information it contains.


2. Review identities and privileged access


Confirm that multifactor authentication is enforced, especially for administrators and remote access. Remove stale accounts, separate daily-use and administrative identities, and review vendor and contractor access. Access should match each person’s actual role—not simply remain in place because it was granted years ago.


3. Confirm that useful logging is enabled


Logs should help answer who signed in, from where, what they accessed, and what changed. Verify that important audit logs are enabled, retained long enough to support an investigation, and reviewed through alerts or routine monitoring. A log that exists but is never checked provides limited protection.


4. Revisit vendor agreements and escalation contacts


Confirm which vendors are business associates, where the applicable agreements are stored, and who must be contacted during an incident. Review notification expectations, security responsibilities, data return or destruction terms, backup and recovery commitments, and the process for obtaining relevant records during an investigation.


5. Practice the first day of a cloud incident


Document the first actions your team would take if cloud data might have been accessed: preserve evidence, disable or restrict affected access, rotate credentials where appropriate, contact the right internal and external parties, maintain patient-care workflows, and begin the required legal and regulatory assessment. Test the plan before an emergency exposes missing contacts or unclear authority.


What this means for your practice


Amgen’s disclosure does not prove that every cloud system is unsafe. It shows why “the vendor handles security” is not a complete operating model. Healthcare organizations need visibility into their own users, data, configurations, contracts, logs, and response procedures—even when a third party hosts the technology.


A practical review does not have to begin with a massive project. Start with the systems holding the most sensitive information and supporting the most important patient-care processes. Identify the highest-risk gaps, assign owners, and build a realistic improvement plan.


A sensible next step


Vault Technologies helps healthcare organizations understand where technology risk may affect privacy, operations, and care continuity. A Technology Health Assessment can help establish a clear starting point for reviewing access, cloud governance, documentation, vendor dependencies, and recovery readiness.


Ready to see where your organization stands? Start your Technology Health Assessment or contact Vault Technologies to discuss your environment.


Sources:


Amgen Form 8-K, filed July 31, 2026

HHS Guidance on HIPAA and Cloud Computing

Recent Posts

By BSFM4465 August 3, 2026
This is a subtitle for your new post
Healthcare IT administrator reviewing N-central cybersecurity alerts and managed endpoint activity o
By michael August 3, 2026
N-central attacks reached managed endpoints. See what healthcare organizations should verify with their MSP after CVE-2026-18577 was actively exploited now.
Maryland medical group ransomware attack exposed patient records, leading to class-action lawsuits
By michael July 6, 2026
A January 2025 ransomware attack on a Maryland medical group exposed 934,000 patient records and triggered class-action lawsuits. See what proactive IT management would have changed.
Dental ransomware attack case study: $350,000 HIPAA settlement — Vault Technologies
By michael June 29, 2026
A 2020 dental ransomware attack led to a $350,000 HIPAA settlement after a 2-year disclosure delay. See what proactive monitoring and incident response would have changed.
By michael April 16, 2026
Vault Technologies Case Study — Synology 4‑Bay NAS Recovery for GoodGardens
By michael March 12, 2026
This is a subtitle for your new post
By michael March 12, 2026
Case Study: Emergency Data Recovery for a Time‑Sensitive Project
By michael February 24, 2026
Why Vault Technologies Is Becoming Oregon's Trusted IT Partner for Senior Care — and Beyond In a crowded field of MSPs, most companies promise the same things: "fast support," "reliable service," "expert technicians." But the organizations we serve aren't looking for another generic IT provider. They're looking for a partner who understands the stakes of what they do — and shows up with the discipline, documentation, and clarity to match. That's exactly why Vault Technologies was built. As a Service-Disabled Veteran-Owned and Woman-Owned business, we built Vault on the values that shaped our careers: precision, integrity, and accountability. We don't believe in vague promises or confusing pricing. We believe in clear expectations, transparent processes, and IT support that feels like a partnership rather than a gamble. That's what makes Vault different — and it's the thread running through everything we've built since. Built on Discipline, Documentation, and Trust Most MSPs operate behind the curtain. Clients rarely know what's happening, what's included, or what they're paying for. Vault Technologies takes the opposite approach. We document everything. We communicate proactively. We set boundaries clearly. We price transparently — flat, per-seat, per-month, with no hourly billing surprises. Our clients know exactly what we do, how we do it, and what to expect at every step. That clarity builds trust — and trust is the foundation of every long-term partnership we have. A Rare Hybrid: IT Expertise and Clinical Understanding One of the biggest gaps in healthcare IT is the divide between people who understand technology and people who understand care delivery. Most MSPs only know the former. Vault closes that gap. Our co-founder Kristina brings 15 years of nursing experience, including hospice and home care, to every conversation we have with assisted living, home health, and hospice clients. We don't just know what EHR downtime looks like on a dashboard — we know what it means for a med-pass window or a shift change when systems fail. That's a hybrid skillset almost no other MSP in Oregon can offer, and it's why we built our service tiers — Foundation, Continuum, and Vigil — specifically around the realities of shift-based care, not a generic 9-to-5 business clock. A Partner Built for Other MSPs, Too Vault isn't just direct-to-client. We're also structured to support other MSPs who need additional capacity without the overhead of hiring. Through our white-label and subcontracting model, we offer: Overflow ticket capacity when an MSP's queue gets ahead of them Standing capacity partnerships for MSPs ready to free up their senior techs Full-scope backend delivery for MSPs that want to focus on sales and relationships while we run help desk, NOC, security, and M365 administration behind the scenes Every tier comes with clear, published pricing and a transparent application process — because the same documentation-first approach we bring to direct clients applies to our MSP partners too. Certified and Ready for Government and Prime Contracting As a certified SDVOSB, VOSB, WOSB, and EDWOSB small business, Vault is also positioned to support federal, state, and local agencies, as well as prime contractors building out their subcontracting base. We're registered in SAM.gov and eligible for set-aside and sole-source opportunities — backed by the same audit-ready documentation and disciplined execution that defines how we operate everywhere else. Veteran Values, Applied Everywhere We Work Being veteran-owned isn't a marketing slogan for us — it's a mindset. It shows up in how we communicate. It shows up in how we document. It shows up in how we treat clients and partners alike. It shows up in how we build systems that scale — whether that's a single assisted living facility or an MSP partner's entire book of business. Why Organizations Choose Vault Technologies Organizations across Oregon and beyond choose Vault because we offer: Clear, transparent, per-seat pricing Professional, jargon-free communication Documented, audit-ready processes Veteran-level discipline Real clinical understanding for senior care and home health A scalable model for MSP partnerships and government contracting A modern, approachable brand built on substance, not slogans We're not trying to be the biggest MSP in Oregon. We're becoming the most trusted — for the care organizations who depend on us, the MSPs who partner with us, and the agencies who need a certified, capable small business they can rely on. The Future of Vault Technologies  Our mission is simple: become the most trusted IT partner for the organizations that value clarity, reliability, and professionalism — whether that's a senior care facility that can't afford technology failure, an MSP looking for a dependable subcontractor, or an agency seeking a certified small business partner. This is the standard we hold ourselves to, and the standard our clients and partners have come to expect.