It's a great question to differentiate sales critters: the new ones are sure that they can work something out; the middle ones are dubious; the experienced people chuckle and disengage politely.
Those that specialise in holding other party's data like this will have liability insurance to cover significant events financially (though there is of course still reputational risk to consider) and processes in place to try make sure such events don't happen so calling on that insurance never needs to happen.
> if someone hosting your data gets hacked
It wouldn't be if any someone got hacked, just if something they are responsible for fails and enables a data leak, so they are not accepting third-party risk unless they themselves involve third parties in the mix. Proving you are not the source of a leak could be an interesting proposition though.
My employer for instance has put a ban on deploying anything new on AWS/Azure/Google Cloud until legal issues have been settled after Privacy Shield was invalidated.
Everything new right now needs to be on EU/EFTA data centers run by EU/EFTA companies. This essentially means self hosting since most clouds are owned by US companies.
Eventually we caved and pushed their account execs to support a “secure” private cloud that passed our IT teams compliance criteria. Fun times!