URL: Federal Agencies Issue Frequently Asked Questions on Identity Theft Rules
I believe that eventually companies will be held liable for identity thefts; particularly if the personal information was stolen from a company. A court, or jury, will eventually decide that a company has a duty to protect personal identity data, and failing to prevent the theft of that data is negligence.
So, how can a company protect itself? Follow the advice and recommendations of a federal agency. Incorporate these recommendation into your standard operating procedure. Enforce compliance and develop a quality/assurance test to ensure compliance.