Ouch!

My thoughts exactly...
It's the fact it took so long to inform clients of the breach that worries me most. I might be wrong being on the other side of the pond but I thought the states have breach notification laws for this kind of event?
Also why is obviously important data stored on unencrypted media being transferred by a third party between sites? Glad it's not my signature on the risk-assessment/cost-benefit analsis for that one.