PrivacySignal
Breach

Biotech giant Amgen says patient data stolen from third-party cloud systems

The Record · · International · Data Breaches

Amgen has disclosed to regulators that patient information and proprietary company data were accessed through a breach affecting third-party cloud systems the company relied on. The incident adds to a growing pattern of healthcare and biotech firms suffering data losses through vendors rather than their own internal infrastructure.

Why this matters: Patient data at a biotech company is not just names and emails. It can include diagnoses, clinical trial participation, genetic information, and treatment histories — things people shared with a healthcare system, not a cloud vendor they never heard of. When the breach happens at a third party, accountability gets murky fast. Amgen made the choice to store sensitive data in those systems. That choice carries responsibility. The fact that someone else's infrastructure failed does not change whose patients were exposed.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
CyberScoop · · US Federal

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

The true cost of a ransomware attack, with and without BCDR

The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

xHealth Data Breach Affects 118,000 Individuals

zHealth, a software company that provides practice management and electronic health records tools to medical practices, has disclosed a data breach affecting approximately 118,000 people.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
DataBreaches.net · · International

Payroll system of mosques, madrasahs hit by ransomware; staff details potentially compromised

David Sun reports: The payroll system of mosques and madrasahs overseen by the Islamic Religious Council of Singapore (MUIS) has been hacked and held for ransom, The Straits Times has learnt. The SmartHRMS human resources (HR) system is supplied by Singapore-based software vendor Avelogic. The latest cybersecurity incident notice on Avelogic’s website, which was last... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →