Independent Reviews
Back to VPN Security News
Data BreachPublished 1 Aug 20266 min read3 sources

Amgen Cloud Breach: Patient Health Data Was Stolen, the Company Says

Amgen disclosed a material cybersecurity incident involving third-party cloud environments, saying proprietary data, patient protected health information and other information were exfiltrated.

Quick takeaways

  • Amgen told the SEC it identified unauthorised activity involving data stored in third-party cloud environments and learned that some data had been exfiltrated.
  • The company says the stolen data includes proprietary data, patient protected health information and other information, while Reuters reports Amgen has not found an impact on products, manufacturing, financial reporting systems or its ability to meet patient needs so far.
  • A VPN can protect your connection when you access healthcare accounts, but it cannot recover patient data stolen from a company's cloud environment.

What happened?

Amgen filed an 8-K with the US Securities and Exchange Commission on 31 July saying it had identified unauthorised activity involving data stored in cloud environments hosted by third-party cloud service providers. The company said it has since learned that some of its data was exfiltrated from those environments.

The filing says the exfiltrated information includes proprietary data, patient protected health information and other information. Reuters reported that Amgen determined the incident was material on 29 July after evaluating the number of files that appeared to be affected and the possibility that those files contained sensitive information.

Why it matters

Healthcare and pharmaceutical data can be especially sensitive because it may connect identity details with treatment, patient-support programmes, prescriptions, trial participation or other medical context. Even when a company is still investigating scope, patients should treat confirmed protected-health-information exposure as more serious than a routine marketing-list leak.

Reuters reported that Amgen has activated its cybersecurity response plan, put containment measures in place and brought in independent forensic experts. It also reported that Amgen had not found an impact so far on products, manufacturing operations, financial reporting systems or its ability to meet patient needs.

What you can do now

If you have used Amgen medicines, patient-support programmes or clinical services, watch for official notices and read the exact data categories listed for you. Use contact details from Amgen's known website, your clinician, insurer or an official mailed notice rather than links in unexpected emails or texts.

If a notice says identifiers, health information or financial details were involved, consider credit freezes or fraud alerts where appropriate, save the notice for disputes, and monitor insurance, pharmacy and explanation-of-benefits paperwork for unfamiliar activity. Be suspicious of callers who already know medical details and pressure you to confirm more information.

Where a VPN helps — and where it does not

A VPN helps when your local network is the risk: for example, checking a patient portal, pharmacy account or insurance site on airport Wi-Fi, hotel Wi-Fi or another network you do not control. It can reduce local snooping and make ISP-level browsing records less revealing.

A VPN does not remove data from Amgen's cloud providers, stop criminals from using already stolen patient information, make a breach notice authentic or replace account security. Use a VPN as one privacy layer, then rely on breach-specific steps such as notice verification, password changes, MFA, monitoring and credit protections where relevant.

VPN Rocks view

This is a good example of where privacy advice has to be honest. Encryption and VPNs can protect data in transit, but they cannot control every third-party system a healthcare company uses after data has been collected.

For readers, the calm checklist is: verify the source of any notice, understand the data involved, secure related accounts, watch for medical-themed phishing and take stronger identity-protection steps if government IDs or financial details are confirmed in your individual notice.

Sources and further reading

VPN Rocks adds plain-English analysis and practical advice. Source links are included so readers can check the underlying guidance directly.

Useful next steps