This story is almost 3 years old. Since then lots of companies and universities have lost customer/student information. It's a tough problem to solve in the real world. As someone who does data security for a living, I sometimes find companies' lack of attention to details to be mind boggling but at the same time, I understand that a good data security policy costs money and the benefits aren't immediately tangible to those who sit in the corporate boardrooms. On the one hand, I'd like to see legislation passed that levies crushing penalties against entities who lose personal information unless they can demonstrate that said information was securely encrypted. On the other hand, if such legislation is passed, companies will simply neglect to report data losses. It seems clear, though, that allowing companies to police themselves isn't working.