Yes very secure.
Yes very secure.
For starters the data generated by a single hospital EHR is something like 10-20 TB/year.
The data is stored (essentially indefinitely) in multiple databases of varying availability, formats and interfaces. It is generally on prem, with multiple failover systems as well as long term backup and a read-only failover usually in the cloud.
Somewhere in this process the data is stored in a non-clinical use data warehouse which has strict physical and digital access restrictions and detailed logs.
Backups are obviously automated. Logs cannot disclose protected health information.
IT accessing individual records would always be flagged to the CIO and CPO offices and audited.
A % of providers are randomly audited by the same offices and certain accesses automatically trigger an audit (for example if I open my own chart, or if I open the chart of a patient who has restricted access - this is audited even if I’m part of their care team and state so in the prompt that comes up when I open the chart).
Physical access by infra providers is disclosed and audited as well.
It’s actually quite secure largely because the fines for failing to do so are quite hefty for the hospital.
The responsibility remains with the user rather than the cloud provider to ensure compliance but they will do their part if you set things up correctly.