I was reading about the CareCloud breach, where data belonging to 3.75 million patients was reportedly exposed, including medical records, payment information, addresses and government IDs.
It got me thinking about something that feels easy to overlook in day-to-day work.
People put all kinds of information into Jira and Confluence like customer details, IDs, payment information, logs, credentials, internal documents, attachments, etc. Usually there's no bad intention behind it. Someone is troubleshooting an issue, helping a customer, sharing a log, or just trying to get something done quickly.
But what happens when sensitive data ends up there by mistake?
The problem I see is that you might not even know it's there. A sensitive value could be sitting in an old ticket comment or attachment for years without anyone noticing it.
And by the time someone discovers it, it may have already been accessed, exported, backed up, or picked up by another integration.
So I'm curious — how are you guys actually dealing with this problem?
Do you have anything that regularly checks Jira/Confluence for sensitive data, or is it mainly based on user awareness and permissions?
And when something is found, who is responsible for dealing with it? Do you have a process to remove or redact it, or does it usually become a manual cleanup exercise?
I'm especially interested in how teams handle the old data problem. It's relatively easy to tell people “don't put PII here” — but what about everything that's already sitting in the system?
Would be interested to hear what others are doing here.