As long as companies find it less expensive to deal with a data breach than to protect the personal data of customers & employees, there will continue to be major data breaches.
In the case of Anthem's loss of our Social Security numbers and birth dates, the news reported they did not even bother to encrypt that critical data.
Unlike stolen credit cards, we cannot get new social security numbers or birth dates, so we will forever be at risk. Yet, there is no law requiring encryption of such data nor requiring companies to pay any penalty.
Companies that want to retain OUR data (it belongs to us, not them) must be forced to protect that data using whatever means necessary. Since the victims suffer, not the company breached, the companies should pay the victims for their time, stress, etc



