we need to flip the conversation on this.
journalists don't seem to grok the fact that breaches are totally the fault of the breached site. sure, the attackers are bad people, but that's a different crime.
we need something close to a death sentence for sites that allow themselves to be breached. mandatory $10k per exposed SSN, $10 per exposed email, that sort of thing.
what would be the result? only good: sites should not be storing this data themselves. the real conversation-flip is that we need to put people in charge of their own data, and make it radioactive for data-users (like Delta Dental) to store it. this kind of data should only live in facilities that are solely run for the purpose, and which provide the data-subject with full control. who pays? not really that hard - some combination of the data-subject, data-users (transaction fees), perhaps just a governmental single payer (since we're talking tiny cost).
imagine if you could look at your data (you can't today!) and could explicitly share out bits to particular data-users. all your records (dental, tax, CC, banking).