This summary provides an overview of key points from the document:
1) Enforcement of HIPAA security standards was initially lacking when they took effect in 2005, with compliance being below 25%. However, high-profile breaches, clearer regulations, and penalties from the Obama administration have increased enforcement and compliance.
2) A recent example is CVS Caremark being fined $2.25 million and required to fulfill obligations over 20 years after exposing patient health records.
3) Health care organizations face challenges in information security due to the nature of aggregating complete patient health histories, as well as generally being behind other industries in adopting new technologies. Factors like securing necessary funding and gaining staff buy-in for security