I have gotten several notices of medical data being leaked over the last two years. I thought HIPPA law had very harsh fines for this, but I guess they just look the other way.
unfortunately, even if the fine seems harsh, if it is less than the profits generated the fine is an operating expense and not a deterrent.
Seems like if you just disclose and make assurances that "you take security seriously" then it's fine.