By Nwafor Sunday
Oluwasanya Ogunsakin, a Cloud Infrastructure Engineer at Digital Health and Care Wales, United Kingdom played a lead role in the migration of 350 NHS Wales public health servers from on-premises infrastructure to the cloud. With over nine years of experience spanning Google Cloud Platform, Azure, and AWS, and a strong academic foundation in Computer Information Systems from the European University of Lefke and Management with Business Analysis from Bournemouth University, Ogunsakin in this interview shares insights into the technical, regulatory, and operational challenges of the project and what it means for the future of public health data management in Wales.
Can you walk me through the background of the NHS Wales public health data migration project and explain what necessitated the move from on-premises to cloud infrastructure?
The migration project stemmed from a critical need to modernise legacy infrastructure, reduce operational overheads, and ensure greater scalability and resilience across NHS Wales’s public health services. The existing on-premises infrastructure was becoming increasingly difficult to maintain and scale in response to growing demand for digital healthcare delivery, real-time data sharing, and security. Cloud adoption presented an opportunity to build a more agile and responsive platform to support population health initiatives, especially in a post-COVID world where data-driven decision-making became vital.
What were the main objectives and goals of the 350-server migration, and how did they align with NHS Wales’s broader digital transformation strategy?
The 350-server migration was Phase 1 of a wider strategy to build a unified, cloud-native foundation for delivering digital healthcare. Objectives included improving uptime and reliability, automating deployments, centralising monitoring and logging, and strengthening security posture. This aligned with NHS Wales’s digital transformation roadmap, which prioritises cloud-first architecture, data interoperability, and patient-centric digital services. The ultimate goal was to lay the groundwork for advanced analytics, AI-driven diagnostics, and seamless integration across NHS systems.
Which cloud platforms and tools were utilised during the migration, and why were those specific choices made?
The project primarily utilised Microsoft Azure for its NHS-aligned compliance offerings and seamless integration with Microsoft Defender for Cloud and Azure Arc. Terraform was chosen for infrastructure-as-code provisioning to ensure repeatability, scalability, and compliance across multiple environments. Azure DevOps was used for pipeline automation, and Microsoft Sentinel for security monitoring. Azure’s compatibility with hybrid deployments and support for services like Azure Policy, Key Vault, and the Azure Monitor Agent made it the ideal platform.
What types of data and systems were migrated during the 350-server phase? Were specific databases, electronic health records, or other components involved?
The migration included critical public health systems such as disease surveillance platforms, analytics databases, and secure API services used by local health boards. Databases migrated included PostgreSQL and SQL Server workloads, as well as file-based clinical data stores. Although core Electronic Health Records (EHR) remained on specialised platforms, the supporting infrastructure for data pipelines, anonymisation services, and secure data exchange gateways were part of the 350-server scope.
As the Lead Infrastructure Engineer, what were your specific responsibilities throughout the project, from planning through to execution?
As Lead Infrastructure Engineer, I was responsible for designing the target cloud architecture, defining IaC modules with Terraform, enforcing security baselines using Azure Policy, and coordinating the migration timeline with application owners. I also oversaw cost optimisation, role-based access control (RBAC), and automated VM provisioning through Azure DevOps pipelines. Post-migration, I led security auditing and performance tuning to ensure SLAs were met.
How did your expertise in Terraform, multi-cloud architecture, and security auditing influence the design and implementation of the migration?
My deep experience with Terraform enabled us to build modular, reusable code that accelerated deployments and simplified rollback procedures.
Understanding multi-cloud principles helped avoid vendor lock-in while maintaining architectural flexibility. Security auditing experience shaped our use of Azure Security Center, Defender for Cloud, and the design of custom Azure Policies to enforce encryption at rest, just-in-time VM access, and endpoint protection via Microsoft Defender for Endpoint.
What major technical or organisational challenges did your team face during the migration, and how were they addressed?
Organisational challenges included coordinating across multiple health boards, each with unique compliance and governance concerns. Technically, some legacy workloads were tightly coupled to unsupported OS versions or hardcoded IPs. We addressed this by creating staging environments for app refactoring and utilising Azure Arc to extend policy enforcement to hybrid machines. We also conducted multiple dry runs to refine the sequencing and cutover strategy for minimal disruption.
Were there any concerns around data sensitivity or downtime during the transition? How did you ensure minimal disruption to healthcare services?
Absolutely. Public health data is extremely sensitive, and downtime could disrupt service delivery. To mitigate risk, we implemented a blue-green deployment strategy and replicated workloads in sandbox environments for validation. Data was encrypted at rest and in transit, and we scheduled migrations during off-peak hours. Real-time monitoring via Azure Monitor and alerting via Sentinel allowed for proactive incident response.
How does cloud migration improve compliance with data protection regulations such as HIPAA, ISO standards, the NHS Data Security and Protection Toolkit, and GDPR?
Migrating to Azure helped ensure tighter compliance with frameworks like ISO/IEC 27001, GDPR, and the NHS Data Security and Protection Toolkit. We used Azure Policy to automatically audit and enforce compliance rules, while integration with Microsoft Defender ensured endpoint compliance. Role-based access, identity federation via Azure AD, and secure logging practices allowed us to meet or exceed data protection standards.
Can you provide examples of specific security enhancements, such as encryption or access controls that were introduced through the cloud infrastructure?
Key enhancements included: Azure Key Vault integration for storing secrets and certificates, Customer-managed keys (CMK) for full control over encryption, Just-in-Time (JIT) VM access, reducing attack surface, Privileged Identity Management (PIM) to govern elevated access, Conditional Access policies tied to compliant devices and MFA, and Log Analytics and Defender for Cloud integrations to detect anomalous activity.
What measurable outcomes or improvements have been observed since the migration of the 350 servers?
We’ve seen a 40% reduction in incident response times due to centralised logging, 99.98% uptime across migrated services, enhanced cost visibility and control through Azure Cost Management, improved threat detection with real-time alerting via Sentinel, quicker provisioning cycles (from weeks to minutes), streamlined compliance audits due to policy-based enforcement.
You mentioned that you are working on migrating an additional 2,050 servers to the cloud over the next ten months. How do you believe this migration will further support public health objectives and modernise patient care across NHS Wales?
This next phase will bring nearly the entire NHS Wales public health stack into the cloud, enabling true interoperability, advanced analytics, and proactive patient care. It will allow real-time data sharing across health boards, support AI-driven research, and improve pandemic preparedness. By modernising infrastructure at scale, we’re creating a foundation for smart hospitals, personalised care, and data-driven policymaking that enhances the wellbeing of every citizen.
Looking beyond the technical benefits, how will this cloud migration project impact society as a whole and contribute to improved healthcare outcomes across Wales?
The societal impact of this migration is profound. By moving NHS Wales’s infrastructure to the cloud, we’re enabling faster, more accurate decision-making across the healthcare system. This means quicker identification of disease outbreaks, more responsive emergency care, and greater accessibility to services in rural or underserved areas.
From a patient’s perspective, this translates into more personalised care, shorter waiting times, and better resource allocation. On a public health level, it enables policy-makers to make data-informed decisions that can prevent illness and reduce health inequalities.
Importantly, the project lays the groundwork for future innovations like predictive health models, AI-assisted diagnostics, and remote care—ultimately shifting the focus from reactive treatment to proactive, preventative care. It’s a transformation that benefits not just the NHS, but every individual and community in Wales.
Disclaimer
Comments expressed here do not reflect the opinions of Vanguard newspapers or any employee thereof.