If a company decides to collect, store and profit off of my personal data and they lose it, I really don't care about "best practices". They profited from my data, they have to pay if they lose it. The company always has the choice of not storing the data in the first place, if they can't bear the risk of a substantial fine in case my data is disclosed.
Perfect security is impossible, but let's not forget 1) who is harmed, or 2) who is getting rich and who will in a worst case will cut their losses, go bankrupt, then start another company with the accumulated weath.
I'm allowed access to the information, and can request that it be updated. They can't keep the information longer then is necessary, they can't use it for anything other than the original collection purposes, they have to take reasonable measures to secure it, they can't disclose it etc.
I won't harp on about the details, but it's relatively well thought out (apart from some limitations regarding the reporting of breaches, but there are changes in the pipeline to patch that up).
So the real issue should be: When and how will a new secure form of identity be created, used, and made available. Social security numbers were never intended to be used in the manner in which they are.