Overview

Amgen, one of the world's largest pharmaceutical manufacturers, has disclosed a data breach in which threat actors accessed and exfiltrated patient health information and proprietary corporate data stored across multiple cloud environments managed by third-party service providers. The company confirmed the breach involved data held outside its own internal infrastructure, placing responsibility partly on vendors entrusted with sensitive information.

‍​​​‌‍The incident adds Amgen to a growing list of large healthcare-adjacent organizations whose exposure has come through third-party cloud arrangements rather than direct intrusion into primary systems. Amgen has not publicly detailed the number of patients affected or the specific cloud providers involved.

While Amgen is a pharmaceutical manufacturer and not a traditional covered entity under HIPAA, the company handles patient data through clinical trials, specialty pharmacy programs, and patient-support services — relationships that can create business associate obligations and expose patient records to the same regulatory and legal risks that govern health plans and providers.

‍​​‌​‍## Key developments

Third-party cloud systems were the entry point. The breach did not originate within Amgen's own data centers but in cloud environments operated by external vendors, a pattern that reflects a structural vulnerability in how large organizations distribute sensitive data across the supply chain.

Both patient health information and proprietary data were taken. The dual nature of the exfiltrated data — clinical or patient-facing records alongside corporate intellectual property — suggests attackers either had broad access to poorly segmented cloud storage or conducted a deliberate, targeted campaign against high-value data categories.

Notification timelines and scope remain unclear. Amgen has not publicly confirmed when it discovered the breach, how many individuals are affected, or whether state breach-notification statutes have been triggered. ‍​​‌‌‍That ambiguity complicates the ability of affected patients or partners to assess their own risk.

Pharmaceutical companies occupy a complex position in health-data regulation. Clinical trial participants, specialty pharmacy patients, and patient-assistance program enrollees may have their data handled by pharmaceutical manufacturers under contracts that create HIPAA business associate obligations — meaning the regulatory exposure here may be broader than Amgen's status as a non-covered entity might suggest.

Industry impact

Third-party and cloud-vendor breaches have become the dominant vector for large-scale health-data exposure. ‍‌‌​‌‍According to IBM's Cost of a Data Breach Report, healthcare continues to record the highest average breach cost of any industry — $9.77 million per incident as of 2024 — with third-party involvement consistently identified as a cost-amplifying factor. The HHS Office for Civil Rights has repeatedly flagged inadequate business associate oversight as a leading source of HIPAA enforcement actions, and OCR's breach portal shows vendor-related incidents accounting for a disproportionate share of large breaches affecting 500 or more individuals.

The pharmaceutical sector's expanding direct-to-patient programs — specialty pharmacy, patient-support hubs, copay assistance, and clinical-trial enrollment — have steadily increased the volume of identifiable health data flowing through manufacturers. ‍​‌​‌‍That shift has occurred faster than regulatory frameworks have adapted, leaving a gap between the data pharmaceutical companies hold and the compliance infrastructure governing how it is protected.

What this means for independent practices

For independent practices, the Amgen incident illustrates that health data does not stop being their concern once it leaves their systems. The obligation to protect patient information — and to respond when it is compromised — follows the data into every vendor relationship. ‍​‌‌‌‍Practices that have not recently reviewed the chain of custody for data shared with specialty pharmacies, clinical-trial sponsors, or patient-assistance programs should do so now, before a third-party incident forces the exercise under deadline pressure.

What would have prevented this

Vendor security assessments before and after onboarding: Requiring third-party cloud providers to demonstrate security controls through standardized questionnaires, SOC 2 reports, or equivalent attestations — and repeating those assessments on a defined schedule — reduces the risk that a vendor's environment becomes an unmonitored exposure point.

Data minimization and segmentation across cloud environments: Limiting the volume of identifiable patient data shared with any single vendor, and enforcing logical separation between patient health data and corporate proprietary information within cloud storage, limits how much an attacker can extract from a single point of access.

Contractual requirements for breach detection and monitoring: Cloud service agreements should obligate vendors to maintain active monitoring for unauthorized access and exfiltration, with defined escalation and notification procedures — not just reactive forensics after a threat actor has already exfiltrated data.

Privileged access controls on cloud storage buckets and repositories: Restricting which accounts and roles can read or export sensitive data, and auditing those permissions regularly, shrinks the set of pathways an attacker can use even after gaining initial access to a cloud environment.

Continuous audit logging with anomaly detection: Maintaining tamper-resistant logs of all access to cloud-stored patient and proprietary data, combined with automated alerting for unusual download volumes or access patterns, shortens the window between intrusion and detection — reducing the total volume of data an attacker can remove before the activity is interrupted.

Read the original at Bleeping Computer