While we have yet to see much in the way of major changes (or punishment) following the massive Equifax data breach last year, there are many changes being introduced at the state level with regard to breach notification, penalties, whether or not credit reporting agencies can charge you for freezing your credit, and consumer rights in general.  After all, legislators are consumers too. For a quick reference of the legislation being considered in states where you might be affected, bookmark this page:

http://www.ncsl.org/research/telecommunications-and-information-technology/2018-security-breach-legislation.aspx