Patient data left Amgen through someone else’s cloud.

Amgen told regulators a third-party cloud breach exposed patient information and proprietary research — the company bearing disclosure duty was not the one holding the data.

Amgen’s Securities and Exchange Commission filing names no vendor, record count, or notification timeline.

Sources: The Record