> It's a collective action problem that needs collective action. Individual incentive changes aren't going to cut it. Unfortunately many thought leaders in the industry have tried to build a culture of suggesting that the solution to collective action problems is individual iteration.
Most kinds of compliance are linked to legal costs as the ultimate source of consequences, not so for PCI.
The ultimate costs for failing to comply with PCI are the actual costs of card fraud which don’t depend on anything in the legal system. When your regulations are designed and enforced by the entity that actually loses money when they aren’t followed, motivation lines up and they work better.
Medical data is... not that
If HIPAA could pierce the corporate veil, this could no longer occur. Wanna dick around and not do your job as a founder / investor? Your personal assets are on the line.
To stay safe with medical data, however, you basically just need to hit whatever standard you think is reasonable. There's no established standards other than:
1. "PII" encrypted during storage/transfer.
2. Customers can request a download of their data.
3. Customers can request you delete ALL their data.
4. Fast track sec fixes above all other company goals.