Was reading about this -
Data belonging to 3.75 million patients was exposed in the CareCloud breach.
The breach reportedly exposed medical records, payment information, addresses and government IDs.
It got me thinking about something like that in Jira and Confluence.
People are constantly attaching customer details, IDs, payment info, medical data, logs, and files to tickets and pages. Some of it might stay there for years.
Do you use DLP or sensitive data scanning on a regular basis to detect PII in Jira and Confluence, or do you mostly depend on permissions and user awareness?
How are you finding and purging sensitive information from old tickets, pages, comments and attachments?
Would be interesting to know how other teams do this.