Last month, the theft of backup computer tapes for the U.S. military’s TRICARE health system amounted to a major data security breach: the contents of the tapes contained the information of 4.9 million health care beneficiaries, including soldiers and their families. This breach joined a long list of high-wattage episodes — by June, similar incidents at Sony, NASA, PBS, Lockheed Martin, and Citigroup had already led security experts and media outlets to label 2011 the worst year ever for data security breaches.

Like cleanup efforts after a hurricane or earthquake, a data security breach inevitably leads companies to data breach notification — the process of informing both victims and regulatory authorities about the existence and nature of the incident, as well as communicating plans to fix problems created by the breach.