Amgen Data Breach Lawsuit: Patient Health Data Stolen
Data Breach · Biotech · Lawsuit Filed

Amgen Sued Over Cloud Data Breach That Exposed Patient Health Information

Published August 13, 2026
Updated August 13, 2026

This case is about Amgen, the California biotechnology company, which told the SEC in late July that attackers exfiltrated patient health information and proprietary files from cloud systems run by outside vendors. A proposed class action followed six days later — but Amgen has not said how many people are involved and notification letters have not gone out, so most patients have no way yet to know whether they are affected.

Pharmaceutical manufacturing and research setting — class action lawsuit over the Amgen cloud data breach involving patient health information
Amgen develops and sells prescription medicines for cancer, cardiovascular disease, inflammation and rare diseases. The complaint alleges it failed to secure the patient data it collected.
Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements attributed to the complaint below are unproven allegations. Amgen Inc. has not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.

What Is This About?

Amgen Inc. — the Thousand Oaks, California biotechnology company that develops and sells prescription medicines for cancer, cardiovascular disease, inflammation and rare diseases — disclosed in late July 2026 that attackers had taken data out of cloud environments hosted by third-party providers, and that the stolen data included patient protected health information. A proposed class action was filed six days later.

The case is captioned Humphreys v. Amgen Inc., Case No. 2:26-cv-08688. It was filed on August 6, 2026 in the U.S. District Court for the Central District of California — the district where Amgen is headquartered. The complaint pleads two counts, negligence and negligence per se, on behalf of a proposed nationwide class, and alleges that Amgen implemented inadequate data security measures despite knowing the value of the information it held. Amgen has not been found liable and the allegations remain unproven.

Status Complaint Filed · August 6, 2026 Humphreys v. Amgen Inc. · C.D. Cal. · No. 2:26-cv-08688
People Affected Not disclosed Amgen has not published a figure, and the incident had not appeared on the HHS Office for Civil Rights breach portal as of August 13, 2026
Data Involved Proprietary data, patient protected health information and other information Amgen's own wording in its SEC filing; the company has not itemized the specific fields taken
Can I Claim? No — nothing to claim yet No settlement, no fund, no claim form. Individual notification letters had not been sent as of publication

What Amgen Actually Disclosed

The starting point is not the lawsuit. It is Amgen's own filing, and it is worth separating from everything that has been written around it.

In a Current Report on Form 8-K filed with the Securities and Exchange Commission on July 31, 2026, Amgen said that in July it identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. It said it activated its cybersecurity response plan, implemented containment measures and engaged independent forensic experts. It then said it had since learned that some of its data — including proprietary data, patient protected health information and other information — had been exfiltrated from those environments.

The filing puts a specific date on the company's judgment call. On July 29, 2026, Amgen determined the incident was material, citing its evaluation of the volume of files that appeared to have been impacted and the potential that the types of information in those files could be sensitive. Under the SEC's cybersecurity disclosure rules, that determination is what starts the four-business-day clock to file.

Two other statements in the filing matter. Amgen said it had not identified any impact to its products, its manufacturing operations, its financial reporting systems, or its ability to meet patient needs. And it said that, as of the date of the report, it believed the incident was not reasonably likely to have a material impact on its financial condition or results of operations.

That last pairing reads strangely at first — an incident declared material, alongside a statement that it probably will not be financially material. It is not a contradiction. Materiality for disclosure purposes asks whether a reasonable investor would want to know; the financial-impact sentence is a separate forward-looking assessment. The practical translation is that Amgen concluded the incident was significant enough that investors should hear about it, while its investigation was still too early to size.

What the Complaint Alleges

The complaint takes Amgen's disclosure as its factual spine and adds a theory of fault on top of it.

Its central allegation is that the breach was foreseeable. It argues that healthcare and life-sciences companies have been on notice for years that centralized stores of health data are prime targets, points to the volume of large healthcare breaches reported to federal regulators, and contends that Amgen nonetheless failed to implement security measures matching the sensitivity of what it held. The specific failures pleaded include inadequate monitoring for suspicious activity, insufficient access controls and encryption, delayed detection and containment, and retention of personal information longer than any business purpose required.

The negligence per se count borrows two federal standards. It alleges Amgen is a covered entity subject to HIPAA's Privacy and Security Rules, and that failing to use reasonable data security is an unfair practice under Section 5 of the FTC Act. Neither statute lets an individual sue directly, which is exactly why they appear this way — as the standard of care for a common-law negligence claim rather than as counts of their own.

The complaint also quotes Amgen's own published statement that it is committed to the lawful stewardship of personal information it collects and stores, using the company's public commitment to establish the duty it says was breached. That is a standard move in breach litigation, and it is one reason companies' privacy pages routinely show up as exhibits.

On injury, the named plaintiff — described as a Pennsylvania resident and an Amgen patient and customer — alleges attempts to open fraudulent accounts in her name, notification that her information appeared on the dark web, an increase in spam calls and texts, lost time spent responding, and emotional distress. Those are her allegations; none has been tested, and Amgen has not responded to the complaint on the public record.

What Is Not Known Yet

This is the unusual part of the story, and it is the reason a page like this has to be careful. The lawsuit arrived before almost any of the facts that normally define a breach case.

How many people. Amgen has not published a number. The 8-K referenced the volume of impacted files, not individuals. Large health data breaches eventually surface on the federal breach portal run by the HHS Office for Civil Rights, and this one had not appeared there as of publication.
Which vendors. Amgen said the data sat in cloud environments hosted by third-party cloud service providers. It has not named them, and has not described how those environments were reached.
Who did it. Amgen has not attributed the incident. No threat actor has publicly claimed it on the record. Several extortion and data-theft groups were active against cloud and SaaS platforms through 2026, and commentators have drawn lines to them, but no evidence connects any of them to this incident. Treat named attribution you encounter elsewhere as speculation.
Exactly what was taken. Amgen's phrasing is broad. The complaint's much longer list of data categories describes what a company like Amgen collects, not a confirmed inventory of what left the building.

None of this means the incident is small. It means the scope is genuinely unresolved, and any page — including this one — that gives you a hard number today is filling in a blank the company has not filled in.

Why a Suit Arrives Before the Notices

Six days from SEC filing to complaint is fast, and readers reasonably wonder how a lawyer sues over a breach nobody has been notified about yet.

The answer is that the two disclosure regimes run on different clocks. The SEC's rule is investor-facing and tight: once a public company determines an incident is material, it generally has four business days to file. The health-privacy regime is individual-facing and slower, allowing up to 60 days from discovery to notify people, and in practice the forensic work of determining whose records were in which file routinely takes longer than that before letters go out. A public company therefore tells the market about a breach weeks or months before it tells the affected patients.

That gap is a public, dated, quotable admission that data was exfiltrated — enough for a firm to draft a complaint from. Filing early also carries a practical advantage in the plaintiffs' bar: when a case is later consolidated, early filers are better positioned for leadership roles. Expect more complaints against Amgen, and expect them to be consolidated. At least one other firm publicly announced an investigation into the incident before this complaint was filed.

Who Could Be Affected?

The complaint proposes a nationwide class of all people residing in the United States whose information was accessed, exfiltrated or otherwise compromised in the Amgen breach occurring in or around July 2026, excluding Amgen, its officers and directors, and the judicial officers assigned to the case.

That definition is broad by design, and at this stage nobody can map it to a list of names. The practical question — do I have data at Amgen? — is harder than it looks, because a drug manufacturer's relationship with patients is usually indirect. People most plausibly in scope are those who used patient support, copay assistance, prescription reimbursement, nurse-support or similar programs tied to an Amgen medicine, since those programs collect insurance details, diagnoses and prescription histories directly. Simply being prescribed a drug Amgen makes does not by itself put your records in the company's systems.

The reliable signal will be a written notice. Amgen said it is evaluating its legal and regulatory notification requirements and will notify impacted patients where required. No class has been certified, and the proposed definition may change or narrow as the case develops.

Is There a Settlement Yet?

No. Humphreys v. Amgen Inc. is a complaint filed on August 6, 2026, not a settlement.

That means:

• There is no settlement fund.
• There is no claim form.
• There is no payout, and no deadline to act.
• Nothing is required of anyone at this stage.

Filing a complaint is the start of a case, not a finding against the defendant. If the litigation later settles, a court-appointed administrator would mail notices and open a claims process with published eligibility rules and deadlines, and we would update this page and our data breach settlements hub. A high-profile breach at a household-name company reliably attracts fake claim sites within weeks — anyone inviting you to file an Amgen claim or pay a fee right now is running a scam. If it helps to see how the real process works end to end, we explain it in our guide to data breach class actions.

What Should You Do Now?

Nothing is required. A few things are worth doing regardless of how this case turns out, and they are worth doing now rather than after a notice arrives, precisely because the notice may be months away.

Read your explanation of benefits statements. Treatment, prescriptions or equipment you did not receive is the main warning sign of medical identity theft, and it will never appear on a credit report. Our guide to medical identity theft after a data breach covers what to look for.
Consider a credit freeze at all three bureaus. It is free, and it is more protective than a fraud alert — see our comparison of credit freezes versus fraud alerts, and our checklist for what to do when your SSN is exposed.
Be skeptical of contact about your medications. A caller or email that already knows your diagnosis, your insurer or which drug you take is not thereby legitimate. Health data makes targeted phishing far more convincing, which is the specific risk this category of breach creates.
Keep any notice you receive. If a settlement is ever reached, the mailed notice is typically how class members establish eligibility, and it often carries the identifier needed to file.

This page is informational and is not legal advice.

What Happens Next?

Amgen now has a deadline to respond to the complaint. In data breach cases the first move is almost always a motion to dismiss aimed at standing — the argument that class members who cannot show actual misuse of their information have pleaded only a risk of future harm, which under TransUnion LLC v. Ramirez may not be enough for Article III standing in federal court.

This complaint is built to meet that argument. The named plaintiff alleges concrete misuse already — attempted fraudulent accounts, her data appearing on the dark web — rather than resting on risk alone. Whether those allegations hold up, and whether they are typical enough of the class to carry certification, are separate questions a court has not reached.

Two other tracks run alongside the litigation. If Amgen determines that HIPAA-regulated information was involved, the incident will appear on the HHS Office for Civil Rights breach portal with an individual count, and OCR may open its own investigation with findings independent of any lawsuit. Separately, the SEC disclosure means the company's own subsequent filings become a source — a quarterly report that revises the scope or quantifies costs would be a genuine development rather than a rumor.

Additional complaints are likely, and related cases in the same district are typically consolidated before a single judge, with the court appointing lead counsel. Each step takes months. OpenClassActions.com will watch the docket, the federal breach portal and Amgen's filings for a scope figure, notification letters, a ruling on any motion to dismiss, certification activity or a future claim form.

Frequently Asked Questions

I take an Amgen drug. Does that mean my data was stolen?

Not by itself. A manufacturer does not automatically hold the records of everyone prescribed its medicines — those usually sit with your provider, pharmacy and insurer. Data reaches Amgen directly when you enroll in something the company runs, such as patient support, copay assistance or reimbursement services. Even then, whether your specific records were in the affected cloud environments is unknown, because Amgen has not described the scope.

Does an SEC filing mean the same thing as a breach notification letter?

No, and confusing the two causes a lot of unnecessary worry. The 8-K is a disclosure to investors that something material happened to the company. A breach notification letter is a legally distinct communication telling a specific person that their specific information was involved. Amgen has made the first; it has said it is still evaluating the second.

Why does it matter that the data was in a third-party cloud?

Legally, it can matter a lot. If a vendor's environment was compromised, responsibility may be shared, and litigation often expands to include the provider once it is identified. It also shapes the defense: Amgen may argue it exercised reasonable care in selecting and overseeing its vendors, while the complaint's position is that a company cannot outsource the duty it owes to the people whose data it collected. Because Amgen has not named the providers, none of this is resolvable yet.

Was proprietary company data really stolen too?

That is what the filing says — Amgen listed proprietary data alongside patient information. For a biotechnology company, that can mean research and commercial material with real competitive value, and it is part of why the incident was deemed material to investors. It is not, however, something an individual patient can act on, and it plays no role in a consumer class action.

Should I join the lawsuit?

There is nothing to join. A proposed class action covers everyone who fits the class definition automatically if a class is certified; there is no sign-up, and no legitimate party will ask you for money or account details to be included. If the case ever settles, participation happens through a claims process at that point, not now.

Sources

Amgen Inc., Current Report on Form 8-K — SEC EDGAR; event date July 29, 2026, filed July 31, 2026.
Class Action Complaint, Humphreys v. Amgen Inc., No. 2:26-cv-08688 (C.D. Cal. filed Aug. 6, 2026) — complaint PDF.
Courthouse News Service, "Amgen hit with class action over data breach".
The Record, "Biotech giant Amgen says patient data stolen from third-party cloud systems".
BleepingComputer, "Amgen says cloud data breach exposed patient health, proprietary info".
HIPAA Journal reporting on the Amgen cyberattack and data breach.
U.S. Department of Health & Human Services, Office for Civil Rights, Breach Portal — checked August 13, 2026; no Amgen entry posted.
HHS, Breach Notification Rule, 45 C.F.R. §§ 164.400–414.


For more class actions keep scrolling below.
Status Complaint Filed — Proposed Class Action
Case Title Humphreys v. Amgen Inc.
Case Number 2:26-cv-08688
Court U.S. District Court, Central District of California
Date Filed August 6, 2026
Claims Negligence; negligence per se
People Notified Not disclosed — no figure published and no HHS Office for Civil Rights posting as of August 13, 2026
Company Disclosure Amgen Form 8-K (SEC EDGAR)

More Healthcare & Data Breach Cases