In its July 31, 2026 Form 8-K, Amgen said it identified unauthorized activity during July and responded by activating its cybersecurity response plan, implementing containment measures, and engaging forensic experts.

 

What happened

The investigation determined that company data had been exfiltrated, including proprietary information, patient protected health information, and other data. Amgen said it was still assessing whether, and to what extent, the compromised material included confidential business information, intellectual property, research and development records, or patient information. On July 29, the company classified the incident as material, meaning it needed to be reported to investors, after considering the volume of affected files and the possibility that they contained sensitive information.

However, Amgen said it had not identified any effect on its medicines, manufacturing operations, financial reporting systems, or ability to meet patient needs. The company also stated that it did not currently expect the incident to materially affect its financial condition or operating results. Amgen is evaluating its legal and regulatory notification obligations and said it will notify affected patients when required. The investigation remains ongoing, and Amgen has not publicly identified the cloud providers or number of people affected.

 

What was said

According to the Form 8-K, “On July 29, 2026, in connection with our evaluation of the volume of the files that appear to have been impacted and the potential that the types of information in such files could be sensitive, the Company determined that this incident is material.

The Company believes, as of the date of this Current Report on Form 8-K, that the incident is not reasonably likely to have a material impact on the Company's financial condition or results of operations.”

 

Why it matters

Amgen’s filing places the affected information in externally hosted environments, where security responsibilities may be divided between the providers’ infrastructure and Amgen’s access, configuration, monitoring, and data-governance controls. It does not yet establish that the providers’ underlying systems were compromised; stolen credentials, an Amgen-controlled configuration, or another access route could have been responsible.

A Journal of Medical Internet Research study explains that “moving patients’ medical information to the Cloud implies several risks in terms of the security and privacy of sensitive health records.” Related Paubox research notes in its 2026 Healthcare Email Security Report that 28% of email-related healthcare breaches reported in 2025 resulted from vendor and business associate email exposure. Although that statistic concerns email rather than Amgen’s cloud-storage systems, it shows how third-party access can expand an organization’s attack surface.

Precipio breach saw similar unauthorized access to an employee’s cloud-based storage account potentially exposed PHI. Identifying Amgen’s providers and the access method will therefore help determine where controls failed, whether other customers could be affected, and which organizations are responsible for investigation and notification.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Is a BAA still required if the cloud provider cannot decrypt the data?

Yes, a provider maintaining encrypted ePHI is still a business associate, even when it does not possess the decryption key.

 

Who is responsible for protecting PHI stored in the cloud?

Responsibility is shared as the provider may secure its infrastructure, while the healthcare organization may control user identities, permissions, configurations, applications, encryption settings, and the information uploaded.

 

Must a cloud provider report a security incident?

A cloud provider acting as a business associate must identify, respond to, mitigate, and document security incidents.