It is a very common practice among large IT organizations in almost every industry (banking, finance, Healthcare, etc.) that deals with the personal (and/or financial, health) information of its members/customers, to use this data, unmodified, in non production (typically Quality Assurance) environments.
This inadvertently exposes highly sensitive data (for e.g. social security numbers, health claims, bank account details including transactions and balances, addresses etc.) to the entire QA organization (background checked or otherwise, doesn't matter), who are otherwise prohibited from accessing production data.
Request the US government to enact a law that requires all IT firms dealing with public data, to obfuscate all production data before being moved to non production environments



