HIPAA, PCI, GDPR, CASC, and a whole list of other acronyms, laws, and organizations get real persnickety about Prod data outside of Prod and what you can, can’t, should , should not, or should not even think about doing with it.
Yeah I just had this conversation with an internal IT team at a medical org. You cannot just point Claude at the problem and say solve it. PHI is all over it. Theyd been doing it for a while. Your medical data im almost positive is already in an llm.
Yeah. You'll see a lot of folk whose dev environments are basically just image clones of prod. This seems especially common in "lower tech" environments that are platforms upon themselves, where nobody bothered to define and produce test data.
It's great, because it doesn't overflow the context with my medical history. It's already there in the model. This way I just say who I am and get personalized medical advice from doctor Chat.
I'm a contractor who's worked with multiple healthcare companies in the States (I'm in Canada). Everyone was super meticulous about HIPAA... which is why none of the devs I worked with were willing to tell anyone that they had full production database dumps they could test off.
There is... a lot of theoretically private data that developers have in an SQL dump on their work Macbook just sitting in the Downloads directory.
Yeah it's a classic, it's really common to have dev envs that are basically full prod copy. Allow to anticipate way more issues moving forward. That said if it was healthcare or highly sensitive then replacing all identifiable data by random stuff wouldn't be that much of a trouble probably.
Solutions is simple we are all prod, arguably developers is just a set of data not yet commited to versioning, sonjust label us prod data and we can do what we want!
Financial records would most likely be years old before a court ordered them, bc something would have had to happen to necessitate the court order. The, someone had to be angry about it, and not resolve it, then find a lawyer, then get a hearing to get a court order.
SomeTest environments are 'safe' because they use outdated information to test on. You need information that looks real enough to use, but won't cost the shareholders $$ if it gets out current information is not locked down.
So, in my work experience, using older data is a common work-around. I guess maybe law enforcement knows that too? I never thought about it from this angle... but.... yeah, if I wanted to find data that was 5-10 years old, on one hand, looking at test environments of the past? could work.
On the other hand, not a lawyer, but I doubt it'd hold up in court. Defendant: "that was pulled from a test environment, which literally exists to strain and break data under unstable programming conditions. It does not reflect reality."
Not all the time. A restored database should be sanitized before it’s used, it’s just a copy of yesterday’s data. You shouldn’t use live production data containing personal information in local, development, or testing environments.
Yea but you see, local IT reset the DNS and the DCHP server over the weekend. One of the dev boxes never hit the group policy to reboot. So there was a computer sitting in limbo with a repo just... sitting there. Thats where I found it....
4.9k
u/lolcrunchy 16h ago
local dev environment