Currently, we use email/password for authentication, but if our user forgets their password, they can answer their security questions to reset it. To design our list of questions, we worked off of http://www.goodsecurityquestions.com/examples.htm and tried to find questions which were relatively obscure, but not so obscure that users couldn't come up with answers. I suppose we can make "write your own question" an option, but we do think that most users given that option will write too easy a question, like mother's maiden name.
Our app contains a lot of sensitive data, including medical data, and privacy of this data is incredibly important to our business. We have to be attentive to regulation and industry standards -- and you're right that industry standards probably give us some cover -- but we have both the desire and the flexibility to do the right thing.