If a company decides to collect, store and profit off of my personal data and they lose it, I really don't care about "best practices". They profited from my data, they have to pay if they lose it. The company always has the choice of not storing the data in the first place, if they can't bear the risk of a substantial fine in case my data is disclosed.
Perfect security is impossible, but let's not forget 1) who is harmed, or 2) who is getting rich and who will in a worst case will cut their losses, go bankrupt, then start another company with the accumulated weath.
So the real issue should be: When and how will a new secure form of identity be created, used, and made available. Social security numbers were never intended to be used in the manner in which they are.