I can't tell you how many times over the years I've seen tens of millions of rows of sensitive data(e.g. ssn) sitting in databases unencrypted. Software devs as an industry really needs to take this more seriously, but often businesses simply will not allocate the funds to do this right because of minimal risks to the corporation. At least with PCI the companies are forced to take card data security seriously.. but for instance nacha data, not nearly as much.
Absolutely the way to handle sensitive data in every app, so much so that I'm working on an open source version.