Earlier quoted context omitted.
I have only limited experience in the healthcare space when it comes to cloud selection, but I can tell you that every single healthcare company I work with uses Azure. They don't do it because it may or may not be right for their needs. They pick Azure because somewhere along the line the mid- and upper-level managers, including director-level IT people, have been made to believe that anything other than Windows is…
The company I work for does not deal with health-related data so I don't have direct exposure to the issues. But, I think there is something analogous happening with SOX compliance. It is a very expensive and slow bureaucracy that reacts very poorly to change. For example, once I was mortified to find out that due to me randomly logging in to some SOX-covered server, afterward there were multiple meetings between SOX…
SOX is the standard for change management for financial companies to prevent shadow changes that could enable another Enron, Worldcom, or Adelphia style cooking-of-books financial scandal. The idea is that all changes should be fully analyzed for their impact. If a change is found to have been made without going through the controls process then a review and an emergency after-the-fact change record must be created. This leads me to believe you did not just login to a server, unless you weren't supposed to have access in the first place (separation of duties requirement), but actually made a modification to that server without an approved change.
All this means that the system is very resilient and will not suffer random outages but most importantly, in the SOX world, there is no avenue for malicious changes to be introduced to critical financial systems and their data.