Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Enabling HIPAA Compliant in Confluence and Jira Service Management

Godknows Agbodo May 13, 2024

My company is trying to understand whether the HIPAA requirement configuration is for transmission of data via email and push notifications? Atlassian noted that email and push notifications might be redacted to exclude any potential PHI when products like confluence and JSM are tagged.

With what and how would Atlassian detect PHI to redact them via emails and push notification?
Is there a way to see how this redaction would look like?

 

3 answers

1 vote
Dave Rosenlund _Trundl_
Community Champion
May 13, 2024

Welcome to the community, @Godknows Agbodo  👋

As mentioned in Atlassian's HIPPA implementation guide, your Atlassian admin(s) is/are responsible for this using Atlassian Automation.

You may wish to consider working with an Atlassian Solution Partner who specializes in this area for assistance from someone who has done this before.

Meanwhile, if you are lucky, and Atlassian customer (peer) who's done this before may chime in. I added some add'l tags to draw the right eyeballs to your question.

I hope this helps,

-dave

Godknows Agbodo May 15, 2024
Like Dave Rosenlund _Trundl_ likes this
Dave Rosenlund _Trundl_
Community Champion
May 15, 2024

You're welcome, @Godknows Agbodo 🙏

If you found this answer helpful and think it might be useful to others with a similar question, please consider using "Accept answer."

-dave

Like Godknows Agbodo likes this
0 votes
Lindsay Bolan
Contributor
July 15, 2025

Below is a screenshot of the default "Public comment edited" notification template looks like when the "safe customer notifications" setting is on. In short, entire variables are redacted (replaced with those black dots in brackets,) so there is no smart detection to selectively remove sensitive/restricted information. The affected variables are work item summary, work item description, and work item comment text. The variables are show with a lock icon in the "Insert variable" menu.

jsm-redacted-customer-notification.png

This was a change for my group when we moved to a HIPAA-compliant cloud site, so a lot of our service project administrators have adopted some variation on the template below:

image-20250612-170746.png

 

0 votes
gemory July 15, 2025

This is not a feature that redacts PHI. It simply changes the notification templates to only display bare bones information “This person made a change to this work item”. Then the recipient has to click the link and authenticate in Jira to access additional information. It’s honestly a fairly huge issue for a small subset of people in our company, as we receive tons of JIRA notifications (that we want!) but having to click links to view the tickets each time has drastically reduced workflow efficiency in some cases. I wish Atlassian would allow orgs to apply HIPAA compliance at the Project level!!

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
TAGS
AUG Leaders

Atlassian Community Events