Amgen has told the SEC that patient health information was taken from cloud environments run by somebody else
Amgen has disclosed a data breach.
The drugmaker filed a Form 8-K on Friday afternoon under Item 1.05, the heading the form reserves for material cybersecurity incidents, and the disclosure is not about a risk. It is about data that has already gone. Amgen says it identified unauthorized activity in July involving data stored in cloud environments hosted by third-party cloud service providers, and that on detecting it the company activated its cybersecurity response plan, implemented containment measures and engaged independent cybersecurity forensic experts.
What was taken is the part that matters. The company says it has since learned that some of its data, including proprietary data, patient protected health information and other information, has been exfiltrated from those environments. The investigation is still open, and Amgen says it continues to assess whether patient information, confidential business information, intellectual property, research and development material or anything else may have been accessed, acquired or exfiltrated.
Two kinds of material
The filing draws a line that is easy to read straight past.
On 29 July, in connection with evaluating the volume of the files that appear to have been affected and the possibility that the types of information in them could be sensitive, the company determined that the incident is material. A paragraph later it says it believes the incident is not reasonably likely to have a material impact on its financial condition or results of operations. Both can be true. Item 1.05 asks whether an incident is material, which is a question about the event and the trigger for filing at all; the second sentence answers a different question, about the money, and it is the one that would move if the notification bill arrives.
Amgen reports no identified impact to its products, its manufacturing operations, its financial reporting systems, or its ability to meet patient needs.
What the filing does not say
It names nobody. There is no threat actor in the document, no cloud provider, no count of affected individuals and no dollar figure, and the company gives no date for the unauthorized activity beyond the month.
The next step in the document is a notification list. Amgen says it continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients. It has undertaken to amend the filing as information required by Item 1.05(a) is determined or becomes available, which is the mechanism by which the missing numbers, if they come, will come. The report is signed by Jonathan P. Graham, executive vice president, general counsel and secretary.