All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Millions of Americans are still dealing with the fallout from several massive health care cyberattacks. Now, biotech giant Amgen says hackers may have stolen patient health information in another reminder that healthcare remains one of cybercriminals' favorite targets.[1]
The company disclosed on July 31 that hackers accessed cloud storage systems operated by third-party providers and stole company information, including patient health data.
"The Company has activated its cybersecurity response plan, implemented containment measures, and engaged independent forensic experts to assist with the investigation and remediation efforts,” Amgen wrote in an 8-K filing.
Amgen added, "To date, the Company has not identified any impact to its products, manufacturing operations, financial reporting systems, or ability to meet patient needs."
However, due to the stolen material in question and the “number of files that appear to be affected,” Amgen warns that some consumers’ sensitive health data may be impacted. Specifically, they said that “patient protected health information” may have been taken.
Protected health information (PHI) is a legal term under HIPAA that can include information about a person's health conditions, treatment, insurance, or other identifying details collected during the course of receiving care.[2]
All About Cookies reached out to Amgen for comment but did not receive a response before publication.
Amgen’s investigation is ongoing, yet the incident adds to mounting evidence that healthcare has become one of the most attractive sectors for cybercriminals, thanks to the volume of sensitive personal information organizations collect and the complex networks they rely on to deliver care.
Why healthcare has become a prime target
Third-party vendors expand the attack surface
What can patients do to protect themselves?
Amgen joins a growing list of healthcare victims
Healthcare organizations have faced an onslaught of cyberattacks over the past several years, with hospitals, insurers, medical device makers, and pharmaceutical companies all finding themselves in hackers' sights.
Amgen joins a huge number of companies, including Abbott, Medtronic, and Novo Nordisk, all of which have disclosed cybersecurity incidents recently.
Cyberattacks are something of a daily occurrence in the healthcare industry, with nearly half of all healthcare organizations globally experiencing at least one active security intrusion.
Most notable is the 2024 Change Healthcare ransomware attack, which disrupted pharmacies and medical billing across the United States and ultimately affected the personal information of an estimated 190 million people, making it “the largest healthcare data breach” ever reported in U.S. history. The industry is still reeling from the breach.
Taken together, these incidents point to a broader trend: Healthcare organizations continue to attract cybercriminals seeking valuable data, financial gain, or leverage for extortion.
Why healthcare has become a prime target
Medical records rank among the most valuable forms of personal information criminals can steal. Unlike a compromised credit card, which can often be canceled and replaced within days, medical information can remain useful to criminals for years.
A healthcare record may contain a person's full name, date of birth, address, insurance information, treatment history, prescription details and, in some cases, government-issued identification numbers.
That information can be used for identity theft, insurance fraud, highly targeted phishing attacks, or sold on criminal marketplaces alongside other stolen personal data.
Healthcare organizations also rely on interconnected networks of hospitals, clinics, insurers, research organizations, laboratories, and technology vendors that exchange sensitive information every day.
Each additional connection creates another potential entry point for attackers.
Third-party vendors expand the attack surface
The Amgen breach highlights the growing role third-party vendors play in modern cybersecurity incidents.
According to the company's disclosure, hackers accessed cloud storage systems operated by third-party providers.
Organizations increasingly depend on outside companies for cloud storage, analytics, billing, software development, and other critical services. Those partnerships can improve efficiency, but they also increase the number of organizations responsible for safeguarding sensitive information.
For consumers, that means personal data may be stored or processed by several trusted partners behind the scenes, not solely by the company they interact with directly, with or without your knowledge.
What can patients do to protect themselves?
Consumers can't prevent companies from being breached, but they can take steps to reduce the risk of stolen information being used against them.
If you believe your information may have been affected:
- Watch for official breach notifications from Amgen or your healthcare provider explaining what information may have been exposed.
- Review your explanation of benefits (EOB) statements and insurance claims for medical services you don't recognize.
- Monitor your bank accounts and credit reports for unusual activity.
- Consider placing a fraud alert or freezing your credit if sensitive identifying information was exposed.
- Be cautious of phishing, such as emails, phone calls, or text messages claiming to be from Amgen or healthcare providers asking you to verify personal information.
- Enable multi-factor authentication on patient portals and other healthcare accounts whenever it's available.
- Use unique, strong passwords for healthcare accounts instead of reusing passwords across multiple services.
- Conduct a free data breach scan.
Healthcare organizations continue investing heavily in research, manufacturing, and digital services, while cybercriminals keep refining their tactics. Protecting patient information has become a fundamental part of modern healthcare, extending well beyond the walls of hospitals and clinics.