TRUCE: TRUsted Compliance Enforcement Service for Secure Health Data Exchange

dc.contributor.authorKim, Dae-young
dc.contributor.authorJoshi, Karuna
dc.date.accessioned2026-01-22T16:19:00Z
dc.date.issued2025-12-09
dc.description.abstractOrganizations are increasingly sharing large volumes of sensitive Personally Identifiable Information (PII), like health records, with each other to better manage their services. Protecting PII data has become increasingly important in today's digital age, and several regulations have been formulated to ensure the secure exchange and management of sensitive personal data. However, at times some of these regulations are at loggerheads with each other, like the Health Insurance Portability and Accountability Act (HIPAA) and Cures Act; and this adds complexity to the already challenging task of Health Data compliance. As public concern regarding sensitive data breaches grows, finding solutions that streamline compliance processes and enhance individual privacy is crucial. We have developed a novel TRUsted Compliance Enforcement (TRUCE) framework for secure data exchange which aims to automate compliance procedures and enhance trusted data management within organizations. The TRUCE framework reasons over contexts of data exchange and assesses the trust score of users and the veracity of data based on corresponding regulations. This framework, developed using approaches from AI/Knowledge representation and Semantic Web technologies, includes a trust management method that incorporates static ground truth, represented by regulations such as HIPAA, and dynamic ground truth, defined by an organization's policies. In this paper, we present our framework in detail along with the validation against the Health Insurance Portability and Accountability Act (HIPAA) Data Usage Agreement (DUA) on CDC Contact Tracing patient data, up to one million patient records. TRUCE service will streamline compliance efforts and ensure adherence to privacy regulations and can be used by organizations to manage compliance of large velocity data exchange in real time.
dc.description.sponsorshipThis research was partially supported by NSF award 1747724, Phase I IUCRC UMBC: Center for Accelerated Real time Analytics (CARTA).
dc.description.urihttp://arxiv.org/abs/2512.09959
dc.format.extent12 pages
dc.genrejournal articles
dc.genrepreprints
dc.identifierdoi:10.13016/m205x8-0iqp
dc.identifier.urihttps://doi.org/10.48550/arXiv.2512.09959
dc.identifier.urihttp://hdl.handle.net/11603/41528
dc.language.isoen
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department
dc.relation.ispartofUMBC Faculty Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.
dc.subjectUMBC Ebiquity Researh Group
dc.subjectUMBC Knowledge, Analytics, Cognitive and Cloud Computing (KnACC) lab
dc.subjectUMBC Cybersecurity Institute
dc.subjectComputer Science - Cryptography and Security
dc.titleTRUCE: TRUsted Compliance Enforcement Service for Secure Health Data Exchange
dc.typeText
dcterms.creatorhttps://orcid.org/0000-0002-6354-1686

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
2512.09959v1.pdf
Size:
1.92 MB
Format:
Adobe Portable Document Format