Yep, 30 days is the standard. 60 is better. Sometimes people don't realize they have ransomware for 2 weeks.

It's also a different situation. In the EHR field, records are rarely deleted/modified. That's why the recommendation is always to add addendums despite tons of requests to allow modification/deletion of previous notes/charts. A big reason why it's easier to get away with just standard backups in the medical field. Law, now that's a totally different animal.