Background and Objectives: To advance cloud transformation and the deployment of a domestically developed HCI, ensure information security, and achieve unified management of resources across multiple campuses
Guided by the principles of ‘improving the patient experience, enhancing service efficiency, reducing medical errors and controlling healthcare costs’, the hospital launched its IT development initiative in 2007. It has since progressively rolled out over 70 information systems, including HIS, LIS, PACS, the Outpatient and A&E Triage System, the ESB integration platform and the Provincial Healthcare Service Supervision Platform. These systems cover multiple areas such as clinical care, medical management and operational management, ensuring the hospital can fulfil all its tasks on schedule and to a high standard.
In recent years, with the gradual maturation of cloud computing technology, the hospital has defined its objectives for cloud transformation. After comprehensively considering factors such as performance, stability and reliability, it first introduced a hyper-converged architecture in 2019 as the foundational infrastructure for its cloud transformation. From 2021 onwards, the hospital began preparing for innovative transformation by introducing a domestically developed hyper-converged platform, thereby laying the groundwork for a comprehensive transition in the future.
Active-Active and DR Solution for Core Business Systems: Ensuring 24/7 Uninterrupted Operation and Data Security
To ensure the 24/7 uninterrupted operation of its core business systems, the hospital has deployed active-active SmartX ECP clusters, offering an RPO of 0 and a RTO of minutes. Throughout the implementation process, the hospital has consistently adhered to the principle of “data-centric infrastructure security”, ensuring compliance with the 3-2-1-1-0 Platinum Rule for data storage. This entails maintaining at least three copies of data, stored across at least two different types of media, with one copy located off-site and one stored offline, whilst regularly conducting data recovery tests to achieve zero recovery errors.
Currently, the hospital has established two active-active centres and one DR centre, with data stored across these three data centres. The system utilises local backups and off-site replication, whilst the technical DR room employs offline backup technology to ensure data security. Twelve-node active-active clusters have now been deployed in both the new and existing data centres, with six-node high-performance all-flash clusters deployed in the primary and secondary availability domains respectively. Core business servers, including the LIS, integrated platform and research platform, all run on these active-active clusters. These active-active clusters provide an exceptional performance experience and high reliability, whilst relying on real-time synchronised extended clusters to ensure data consistency upon disk write, ultimately achieving RPO=0.
Meanwhile, the hospital has deployed hybrid-flash nodes at the DR centre, periodically replicating active-active data to the disaster recovery cluster. Through asynchronous replication, mutual replication and recovery are achieved across multiple data centres, enabling asynchronous disaster recovery and ensuring business continuity. During service migration, cross-virtualisation platform migration tools are utilised to seamlessly migrate business systems to the active-active cluster, safeguarding normal business operations. Currently, the three data centres—the main hospital data centre, the new building data centre and the DR centre—have established interconnection between the active-active data centres and the DR centre. Multi-replica DR backups have been implemented, effectively safeguarding the reliability and continuity of business system operations and meeting the Level 7 construction standards for electronic medical records.
Cybersecurity Protection and East-West Traffic Management: Ensuring the Security and Business Continuity of Hospital Information Systems
In response to the increasingly severe cybersecurity situation in the healthcare sector, the hospital has focused its analysis on the risk of ransomware ‘spreading within the internal network’ (i.e. ‘east-west’ traffic) and has systematically investigated the feasibility of a secure migration from VMware NSX to a domestically developed platform. The planning and construction objectives are as follows:
- During the gradual replacement of existing VMware services, security levels must not be compromised; existing access control policies must be migrated to the new domestic platform alongside the services;
- Build a new internal network security architecture based on the domestic platform, establishing a distributed firewall covering all virtualised services to enable granular access control for business systems and implement the “zero-trust” security model;
- Align with existing NSX usage practices and security principles, without requiring additional investment in hardware network security equipment;
- To ensure security policies follow the virtual machines (VMs) and enable rapid emergency response, the hospital dynamically binds security policies to VMs: this facilitates the activation and deactivation of security policies during operations and maintenance; in the event of a security incident, the operations team can swiftly locate and isolate affected nodes, preventing the spread of threats and safeguarding the continuity of core business operations.
To achieve the above objectives, the hospital’s “east-west” network security implementation follows an incremental approach of “visualisation first, verification next, deployment thereafter, and normalisation finally”, ensuring that security policies are precise and effective, and that operational management transitions smoothly. First, through a three-month period of traffic visualisation analysis, visualisation tools were utilised to continuously monitor and record normal traffic flows between core business systems (such as HIS, LIS, PACS and EMR), as well as between business systems and databases and middleware. Subsequently, a trial operation was initiated based on baseline policies, with the accuracy of the policies verified and optimised using a “log-only” mode. Based on the traffic baseline established in the first phase, the operations team drafted micro-segmentation security policies on the platform, adhering to the ‘least privilege’ principle. Concurrently, comprehensive operational training and emergency drills were conducted for the operations team to ensure their capabilities were aligned. Finally, once preparations were complete, the policies were smoothly implemented, integrating ‘east-west’ security protection into the routine operations framework.
Outlook for the Future
In advancing its transformation, the hospital has set the ultimate goal of ‘infrastructure supporting application services’, with a particular focus on the seamless migration of business operations. Taking into account both business requirements and the innovation and transformation process, the hospital plans to proceed in phases: first, migrating the most critical data to domestically produced distributed storage, followed by the gradual replacement of virtualisation systems; once the transition to domestic storage and virtualisation has been achieved, Hygon CPU-based servers will be introduced, ultimately realising a full-stack domestication of the infrastructure.
Currently, adhering to the principle of “piloting first”, the hospital has selected a solution with a unified technology stack (the Hygon platform) to expand its existing hyper-converged clusters, thereby achieving unified management of business resources and standardised configuration of security policies across the entire hospital. At this stage, the Office Automation (OA) system and test services have been deployed and have been operating stably for two years since going live. In the future, the hospital plans to support more business systems, moving towards a new phase of innovative transformation.
Using evaluation to drive development, utilisation and reform. The Jiangsu Province Hospital with Integration of Chinese and Western Medicine will further optimise its information systems, upgrade its architecture to support AI, strengthen the digital infrastructure for the inheritance and innovation of traditional Chinese medicine, and continue to advance the optimisation and refinement of information systems centred on electronic health records. At the same time, taking the opening of the new building as an opportunity, the hospital will integrate its various IT resources to enhance the development of a ‘smart hospital’ characterised by smart healthcare, smart services and smart management, thereby supporting the hospital’s high-quality development.



SmartX Case Studies
7 scenarios, 11 selected cases, 54 pages. Include cases in scenarios like Replace VMware, Modernize Infrastructure, Critical Business Apps, General Apps, VDI, Dev & Test, Disaster Recovery, ROBO & Edge.
SmartX ECP Product Portfolio Brief
The SmartX Enterprise Cloud Platform (ECP) offers a versatile enterprise cloud solution catering to both traditional and modern applications.