Biotech giant Amgen says patient data stolen from third-party cloud systems
Amgen has disclosed to regulators that patient information and proprietary company data were accessed through a breach affecting third-party cloud systems the company relied on. The incident adds to a growing pattern of healthcare and biotech firms suffering data losses through vendors rather than their own internal infrastructure.
Why this matters: Patient data at a biotech company is not just names and emails. It can include diagnoses, clinical trial participation, genetic information, and treatment histories — things people shared with a healthcare system, not a cloud vendor they never heard of. When the breach happens at a third party, accountability gets murky fast. Amgen made the choice to store sensitive data in those systems. That choice carries responsibility. The fact that someone else's infrastructure failed does not change whose patients were exposed.
Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.