(1) require the provider by contract to adopt and implement appropriate security measures to protect personal information; and
(2) take adequate measures to monitor and assess whether the provider employed measures to appropriately protect personal information under the circumstances.