Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
HIPAA ResponseCompany DisclosureVerified

Amgen cloud breach disclosure: BAA coverage for cloud-hosted vendors

Amgen disclosed a cybersecurity incident to the SEC involving data held in third-party cloud environments. The filing discloses no individual count. The question it raises for a practice is which cloud-hosted vendors hold PHI under a signed BAA.

Source of record: SEC — registrant disclosureJuly 31, 2026Last verified August 22, 2026

What the source establishes

Third-party cloud environments have become the dominant exposure surface for health data — not because cloud infrastructure is inherently insecure, but because organizations routinely distribute sensitive data across vendor tiers without maintaining proportionate oversight at each layer. When a vendor's cloud system is compromised, the covered entity or business associate that shared the data still owns the notification obligation and the regulatory exposure. The Amgen incident — in which attackers exfiltrated patient health information and proprietary data from cloud systems operated by external service providers, with no public confirmation yet of patient count or discovery timeline — illustrates precisely this structural gap.

What HIPAA requires here

Amgen is a pharmaceutical manufacturer — not itself a HIPAA covered entity, business associate, or clearinghouse — so HIPAA does not directly govern Amgen's own security practices. The HIPAA angle here belongs to the downstream healthcare providers, health plans, and business associates that shared patient data with Amgen through clinical-trial protocols, specialty pharmacy programs, or patient-support hubs, and whose data was exposed via Amgen's vendor cloud environments.

For those downstream covered entities and business associates, §164.314(a) — Business Associate Contracts and Other Arrangements is the provision that governs the relationship: it requires covered entities to obtain satisfactory assurances from business associates that PHI will be appropriately safeguarded, and extends those obligations to subcontractors. Companion provisions include §164.308(a)(1) (risk analysis, requiring identification of threats to PHI wherever it resides) and §164.308(a)(6) (security incident procedures, which must account for breaches originating at vendors). OCR has repeatedly cited inadequate business associate oversight as a leading trigger for enforcement actions, and vendor-related incidents account for a disproportionate share of large breaches on the HHS breach portal.

Patient Protect mapping

  • BAA Management tracks executed agreements by vendor, flags missing or expired BAAs, and stores the documentation your practice needs when OCR asks whether every data-sharing relationship was covered.
  • Vendor & BAA Governance holds every business associate relationship, its agreement, and the state that agreement is in — so a vendor's obligations are recorded and current rather than assumed after onboarding.
  • Security Risk Assessment (SRA) requires you to enumerate every system and relationship through which PHI flows, including specialty pharmacy partners and patient-support programs — creating the inventory that makes downstream exposure visible.
  • Information Systems Inventory maintains a record of where PHI resides across your environment and which vendors touch it, giving you the chain-of-custody documentation needed to respond quickly when a third party discloses a breach.
  • Autonomous Compliance Engine recalculates your compliance state continuously, so a new vendor relationship or a change in data-sharing scope triggers a reassessment rather than waiting for the next annual review.

Controls worth reviewing

  • Audit every active BAA in the near term. Confirm each agreement names the data types covered, includes a breach-notification window shorter than the HIPAA maximum of 60 days, and extends obligations to subcontractors.
  • Map your PHI beyond your walls. Identify every clinical-trial sponsor, specialty pharmacy, or patient-assistance program that has received patient data from your practice and confirm current BAAs are in place.
  • Request subcontractor documentation from cloud-reliant vendors. Ask vendors whether they use subcontracted cloud storage for PHI and require written confirmation that HIPAA protections apply at every tier.
  • Add a third-party breach scenario to your incident-response plan. Your plan should specify how you identify affected records and meet notification deadlines when the breach originates at a vendor, not in your own systems.
  • Schedule vendor reassessments on a defined cadence. A security questionnaire or SOC 2 review at onboarding is a starting point, not a permanent attestation.

Sources

Source of record. Amgen Inc. appears in the HHS OCR breach portal, reported July 31, 2026, with no individual count disclosed. Where this page and the OCR record disagree, the OCR record is correct. The filing does not publish root cause, whether data was exfiltrated, or which categories of PHI were involved; those remain unknown unless a source establishes them.

Secondary reporting. Bleeping Computer. Reporting can establish that something happened; it does not establish what was filed. Written with AI assistance under Patient Protect’s editorial standards.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →