buy Trezor model T (currently 20% off to promote new coinjoin support), use shamir backup and hidden wallets based on additional password for plausible deniability
store your shamir fragments safely and don't be predictable (like mum, dad, office, ...)
follow the best practices, don't try to create your own security policies and protocols - many much smarter guys already explored it all
buy a backup device and initiate it with the same seed (you don't want to do this under pressure later from your backups just because you accidentally stepped on it)
I'd recommend trezor suite but other options should be fine
understand and use coin control
Is there a significant difference in safety between the two options?
there is a massive difference
hot wallet is fine for daily spending and experiments
for anything serious you NEED to store your keys on an offline device with DISPLAY to be able to verify and sign transaction safely, anything less is significant downgrade
btw frequently discussed bluetooth connection is just fine if used properly