Does HIPAA motivate hospitals to take security seriously? The recent outbreaks in cryto-ransomware seem to suggest the answer is 'no.'
https://www.hhs.gov/hipaa/for-professionals/compliance-enfor...
Unfortunately, HIPAA is an incredibly rigid, incredibly broad law, and it's applied to a field in which security practices are incredibly inconsistent.
As a result, HIPAA violations are pretty commonplace, and the vast majority are never reported to HHS, let alone penalized.