{"schema_version":1,"research_id":"eoa_inverse_innovation_exp03_external48_20260801","source_assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","cell_id":"deadweight_loss_reduction__gender_studies","selection_stratum":"HIGH_UPSIDE_RESEARCH_OPTION","search_queries":["site:ucop.edu lived name policy legal name only required documents University of California","preferred chosen name electronic health record transgender primary research implementation legal name","chosen name use transgender youth mental health primary study Russell 2018","site:edu preferred name implementation legal name systems audit policy university","transgender deadnaming electronic health record unwanted disclosure study interviews","transgender students university records preferred name barriers study legal name systems","US transgender survey mismatched identification name harassment official report PDF","implementation preferred name electronic medical record study transgender patients outcomes","UC Presidential Policy Gender Recognition Lived Name 2023 PDF legal name lived name","University California Gender Recognition Lived Name policy implementation systems scope","PubMed Chosen Name Use Linked Reduced Depressive Symptoms 2018 PMID","PubMed Experiences Transgender People Reviewing Electronic Health Records qualitative 2022","University of Iowa Hospitals and Clinics preferred name Epic legal name implementation 2017","site:bls.gov/ooh software developers quality assurance analysts testers median pay"],"sources":[{"source_id":"S1","title":"Chosen Name Use Is Linked to Reduced Depressive Symptoms, Suicidal Ideation, and Suicidal Behavior Among Transgender Youth","publisher":"Journal of Adolescent Health / PubMed","url":"https://pubmed.ncbi.nlm.nih.gov/29609917/","source_class":"PRIMARY_RESEARCH","publication_date":"2018-03-30","accessed_at":"2026-08-02","claims_supported":["In a community cohort of 129 transgender and gender-nonconforming youth, chosen-name use in more contexts was associated with lower depression, suicidal ideation, and suicidal behavior after adjustment for measured characteristics and social support.","The cross-sectional association supports potential importance but does not establish that record-system changes cause improved mental-health outcomes."]},{"source_id":"S2","title":"Experiences of Transgender People Reviewing Their Electronic Health Records, a Qualitative Study","publisher":"Journal of General Internal Medicine / PubMed","url":"https://pubmed.ncbi.nlm.nih.gov/35641720/","source_class":"PRIMARY_RESEARCH","publication_date":"2022-05-31","accessed_at":"2026-08-02","claims_supported":["A community-engaged qualitative study of 30 transgender adults found that wrong names, pronouns, or gender markers in EHRs were common among participants and were reported to erode trust and cause trauma.","Participants and clinicians reported EHR-capability limitations as barriers to quality care.","The small purposive qualitative sample establishes credible mechanisms and experiences, not population prevalence or intervention effect size."]},{"source_id":"S3","title":"The Report of the 2015 U.S. Transgender Survey","publisher":"National Center for Transgender Equality","url":"https://transequality.org/sites/default/files/docs/usts/USTS-Full-Report-Dec17.pdf","source_class":"OFFICIAL_ORGANIZATION_DATA","publication_date":"2016-12","accessed_at":"2026-08-02","claims_supported":["Among survey respondents who had presented identification whose name or gender did not match their presentation, 32% reported at least one negative experience such as harassment, denial of service, being asked to leave, or assault.","The survey documents financial, procedural, and eligibility barriers to updating identity documents.","The nonprobability survey concerns identity documents broadly and cannot estimate unnecessary institutional name propagation at a particular institution."]},{"source_id":"S4","title":"Lived Name for Students","publisher":"University of California San Diego","url":"https://students.ucsd.edu/sponsor/registrar/lived_name_students.html","source_class":"OFFICIAL_GUIDANCE","publication_date":"2026-07-16","accessed_at":"2026-08-02","claims_supported":["UC San Diego permits self-designated lived first, middle, and last names without documentation and restricts access to the legal name.","Legal names remain in specifically required processes, including financial aid, billing, refund checks, and tax reporting, while ordinary mail and email use the lived name.","The implementation uses differentiated access and displays, supports identity verification through campus identification, and acknowledges propagation delays and synchronization gaps across student and employment systems."]},{"source_id":"S5","title":"Lived Name and Reporting","publisher":"UCLA Digital & Technology Solutions","url":"https://dts.ucla.edu/enterprise-data-and-analytics/lived-name-and-reporting","source_class":"OFFICIAL_GUIDANCE","publication_date":"n.d.","accessed_at":"2026-08-02","claims_supported":["UCLA states that a legal name differing from a lived name must be confidential and must not be displayed in documents or IT systems that do not require it.","This is direct institutional prior art for purpose-limited legal-name display and confidentiality."]},{"source_id":"S6","title":"System Procedure 1B.1.2 Preferred Name","publisher":"Minnesota State Colleges and Universities","url":"https://www.minnstate.edu/board/procedure/1b01p2.html","source_class":"OFFICIAL_GUIDANCE","publication_date":"2015-07-28","accessed_at":"2026-08-02","claims_supported":["Minnesota State requires preferred names to be used except where legal or business needs or technical constraints require otherwise.","Where a preferred name is used, the legal name should not appear in the same field; email, directories, and class rosters are named implementation targets.","The procedure assigns central and campus implementation authority, anticipates phased technical work, and calls for periodic review of the field list."]},{"source_id":"S7","title":"Preferred Names, Preferred Pronouns, and Gender Identity in the Electronic Medical Record and Laboratory Information System: Is Pathology Ready?","publisher":"Journal of Pathology Informatics","url":"https://pmc.ncbi.nlm.nih.gov/articles/PMC5653959/","source_class":"PRIMARY_RESEARCH","publication_date":"2017-10-31","accessed_at":"2026-08-02","claims_supported":["The University of Iowa Hospitals and Clinics implemented preferred-name functionality through customized EHR displays and workflows while retaining legal names where required for billing, transfusion, and patient-identification processes.","The implementation encountered downstream-system, label-space, interface, regulation, training, and synchronization constraints.","Medical record numbers and other identifiers can preserve linkage, but some safety-critical workflows require exact identifiers and carefully controlled exceptions."]},{"source_id":"S8","title":"Software Developers, Quality Assurance Analysts, and Testers","publisher":"U.S. Bureau of Labor Statistics","url":"https://www.bls.gov/ooh/computer-and-information-technology/software-developers.htm","source_class":"GOVERNMENT_OR_REGULATOR","publication_date":"2025-08-28","accessed_at":"2026-08-02","claims_supported":["BLS reports May 2024 median annual wages of $133,080 for software developers and $102,610 for software quality-assurance analysts and testers.","The wage data provide a public labor-cost anchor for broad 2026 resource-equivalent bands but do not estimate this intervention's total cost."]}
],"problem_evidence":{"support":"STRONG","rationale":"Primary qualitative research directly documents wrong-name and related EHR harms, a youth cohort associates broader chosen-name use with better mental-health indicators, and a large community survey documents service denial and harassment associated with incongruent identification. Official UC implementation guidance also treats unnecessary legal-name display as a confidentiality problem. These sources establish that the problem can occur and matter, but they do not measure its prevalence, administrative rework, or causal effect at the proposed institution.","source_ids":["S1","S2","S3","S4","S5"]},"stakeholder_evidence":{"support":"MODERATE","rationale":"UC and Minnesota State have adopted institution-wide rules, assigned implementation responsibilities, and created user-facing processes, demonstrating credible authorizer action and stakeholder relevance. The evidence does not show that a particular target institution currently seeks another pilot, nor does it quantify demand among affected users or frontline staff there.","source_ids":["S4","S5","S6"]},"prior_art":{"proximity":"ESTABLISHED_PRACTICE","closest_analogues":[{"name":"University of California Gender Recognition and Lived Name implementation","similarity":"UC guidance already implements the central mechanism: lived names are used broadly, legal names are confidential and visible only in specifically required systems, access is differentiated, and stable institutional identification supports continuity.","remaining_difference":"The candidate adds a bounded, opt-in, low-risk pilot with a purpose audit, an explicit manual-exception comparator, preset outcome measures, and harm-based stopping rules. The reviewed UC materials describe policy and implementation, not a prospective comparative evaluation of those elements.","source_ids":["S4","S5"]},{"name":"Minnesota State System Procedure 1B.1.2","similarity":"The procedure separates preferred and legal names by function, suppresses the legal name in fields using the preferred name, identifies ordinary display systems, assigns governance responsibility, and requires periodic review.","remaining_difference":"Minnesota State retains legal name as the default outside an identified preferred-name list and uses written requests; the candidate proposes beginning with a necessity audit and testing whether purpose-based suppression outperforms discretionary exceptions using predefined outcomes and falsifiers.","source_ids":["S6"]},{"name":"University of Iowa Hospitals and Clinics preferred-name EHR implementation","similarity":"This implementation uses distinct name fields and customized contextual displays while retaining legal identity and stable identifiers for billing, transfusion, and patient-safety workflows.","remaining_difference":"It is healthcare-specific, sometimes displays both names, and reports implementation challenges rather than a controlled comparison of field-purpose suppression against manual exceptions on disclosure, correction, delay, and safety outcomes.","source_ids":["S7"]}],"distinctive_claim_remaining":"Only a comparative implementation-research claim remains plausibly distinctive: at an institution still using default legal-name propagation plus manual exceptions, a prospectively classified field-purpose rule and monitored low-risk rollout may reduce unnecessary exposure and correction burden without increasing record-linkage, identification, reporting, privacy, or safety failures. The name-separation mechanism itself is established practice.","confidence":"HIGH"},"implementation_evidence":{"support":"STRONG","rationale":"UC San Diego documents a functioning lived-name model with restricted legal-name access, purpose-specific exceptions, and identity-verification guidance; Minnesota State assigns implementation across central and local applications; and the University of Iowa report describes actual EHR customization, stable identifiers, training, and safety-critical exceptions. Evidence therefore supports technical feasibility while also showing that downstream interfaces, vendor constraints, synchronization, billing, and regulated workflows can be substantial.","source_ids":["S4","S6","S7"]},"scores":{"meaningful_impact":{"score":4,"rationale":"Wrong-name records are linked to reported trauma and loss of trust, broader chosen-name use is associated with better mental-health indicators, and incongruent identification is associated with service denial and harassment. The specific reduction achievable through institutional field separation remains unmeasured.","source_ids":["S1","S2","S3"]},"stakeholder_pull":{"score":4,"rationale":"Two independent public university systems have adopted formal chosen/lived-name procedures, and UC campuses provide active implementation and support channels. Pull at any new target institution is not yet demonstrated.","source_ids":["S4","S5","S6"]},"incremental_advantage":{"score":4,"rationale":"For an institution whose actual baseline is legal-name propagation plus manual exceptions, purpose-specific defaults could remove repeated user and staff correction work. Existing UC and Minnesota implementations make this advantage operationally credible, although no reviewed study directly compares it with the manual baseline.","source_ids":["S4","S6","S7"]},"distinctiveness_plausibility":{"score":2,"rationale":"Purpose-limited legal-name display, separate lived-name fields, confidentiality, stable linkage, and field lists are already documented practice. Distinctiveness is limited to the proposed comparative audit, opt-in pilot design, outcome measures, and preset stopping rules.","source_ids":["S4","S5","S6","S7"]},"technical_implementability":{"score":4,"rationale":"Multiple institutions have implemented the core functionality. The score is below 5 because actual deployments report customization, propagation lag, disconnected employment and student systems, vendor limitations, label constraints, and regulated exceptions.","source_ids":["S4","S6","S7"]},"adoption_authority_feasibility":{"score":4,"rationale":"The UC and Minnesota State examples demonstrate that central policy owners, registrars, IT divisions, and campus units can authorize and implement such rules. Feasibility remains jurisdiction-, contract-, and workflow-specific, especially in clinical, financial-aid, payroll, and tax systems.","source_ids":["S4","S6","S7"]},"evidence_readiness":{"score":3,"rationale":"Existing systems supply auditable fields, access logs, identifiers, tickets, and interface inventories, and primary research supplies candidate harm constructs. No reviewed comparative study validates the proposed disclosure, avoidance, correction, or serious-error measures, and local baseline data are absent.","source_ids":["S2","S4","S7"]},"safety_net_benefit":{"score":4,"rationale":"The design can retain restricted legal identity, stable identifiers, purpose-specific exceptions, access controls, testing, and rollback. Actual implementations show these safeguards are feasible, but an unwanted disclosure cannot be undone and identity-critical workflows require careful exceptions.","source_ids":["S4","S5","S7"]},"scalability":{"score":4,"rationale":"UC and Minnesota State demonstrate applicability across campuses and multiple system types. Scaling is not frictionless because integrations, field ownership, vendor functionality, and legally necessary name uses vary across domains.","source_ids":["S4","S6","S7"]}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"10K_TO_50K","scope":"A four-to-six-week non-deployment audit at one institution covering a predefined sample of low-risk display and communication interfaces: analyst and project-lead labor; compensated affected-party review; legal, privacy, security, accessibility, and records consultation; secure ticket and workflow analysis; field-purpose classification; data minimization; and a written comparison and evaluation protocol. Existing secure software and equipment are assumed.","confidence":"MODERATE","assumptions":["Relevant schemas, interface owners, tickets, and access logs can be reviewed without substantial data engineering.","The audit uses existing secure workstations and analysis software and makes no production changes.","The band allows fractional analyst, governance, and specialist effort plus participant compensation; BLS technology wages are only a labor anchor."],"source_ids":["S2","S7","S8"]},"initial_deployment_startup":{"band_2026_usd":"50K_TO_250K","scope":"Design and test an opt-in pilot in a small set of low-risk fields, including product ownership, engineering, QA, test environments and devices, permissions and linkage controls, privacy and security review, accessibility testing, consent and support materials, affected-party compensation, vendor coordination, monitoring instrumentation, comparison design, and rollback rehearsal.","confidence":"LOW","assumptions":["The participating systems already support a separate display-name field or configurable integration.","No regulated identity, financial-aid, payroll, tax, transfusion, or high-risk clinical workflow is changed.","A limited number of interfaces are involved and core identity-management software is not replaced."],"source_ids":["S4","S7","S8"]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"A broader launch at one medium-sized institution across multiple approved systems, including program management; software and identity-platform changes; integration remediation; vendor fees; security, privacy, legal, records, and accessibility work; QA and test equipment; migration; communications and training; help-desk capacity; independent outcome evaluation; incident exercises; and contingency reserve.","confidence":"LOW","assumptions":["Launch remains within one institution and excludes wholesale replacement of the core ERP, EHR, or identity platform.","Several legacy or vendor-managed interfaces require modification and regression testing.","The institution retains legal-name exceptions for regulated and safety-critical functions."],"source_ids":["S4","S5","S6","S7","S8"]},"annual_recurring":{"band_2026_usd":"50K_TO_250K","scope":"Annual one-institution operation: data-governance and affected-party council time; access reviews; linkage and security monitoring; software or vendor maintenance; support and correction handling; staff training; incident response; periodic field-purpose reassessment; audit-log storage; and recurring outcome and equity evaluation.","confidence":"LOW","assumptions":["Monitoring uses existing security, audit, and help-desk infrastructure where possible.","The institution operates a moderate number of participating systems.","Major platform replacement, litigation, and extraordinary incident remediation are excluded."],"source_ids":["S4","S6","S7","S8"]}},"verified_pipeline_gates":{"externally_supported_problem":{"status":"YES","reason":"Primary research and official survey data support the existence of wrong-name, disclosure, trust, and access harms, while official institutional guidance recognizes that legal names should not appear where unnecessary. Local prevalence and effect size remain to be measured.","source_ids":["S1","S2","S3","S4","S5"]},"externally_credible_adopter_or_authorizer":{"status":"YES","reason":"UC and Minnesota State provide direct examples of system and campus authorities assigning registrars, IT units, policy owners, and local application owners to implement name-separation rules.","source_ids":["S4","S5","S6"]},"distinct_testable_incremental_claim":{"status":"YES","reason":"Although the mechanism is established, a local incremental claim remains testable: purpose-classified suppression can be compared with legal-name propagation plus manual exceptions on exposure, correction, delay, avoidance proxies, and serious identity or reporting failures.","source_ids":["S4","S6","S7"]},"bounded_next_evidence_step":{"status":"YES","reason":"A retrospective, non-deployment field audit can compare existing interfaces and falsify the local problem before any configuration change or live pilot is considered.","source_ids":["S2","S4","S7"]},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The next step is read-only and can be conducted under existing privacy and data-governance authority. Any later pilot must exclude legally controlled and safety-critical fields until approved; reviewed implementations demonstrate workable exceptions but do not substitute for local legal and safety review.","source_ids":["S4","S6","S7"]},"credible_cost_scope_and_range":{"status":"YES","reason":"The bands are bounded to one institution and explicitly include labor, data handling, compliance, coordination, software, equipment, security, support, and evaluation. Public wage data and documented implementation complexity anchor the ranges, although architecture-specific estimates remain low-confidence.","source_ids":["S4","S7","S8"]}},"next_evidence_step":"Conduct a six-week, non-deployment audit at one willing institution. Pre-register a sample of 12–20 low-risk display and communication interfaces and classify every legal-name use, with independent legal/privacy/records review, as required, plausibly required, or unsupported. Using minimized, de-identified operational data, compare unsupported-propagation frequency and correction-ticket, delay, repeat-contact, and documented-disclosure rates between interfaces that already honor a used-name field and volume-matched interfaces that still propagate the legal name or depend on manual exceptions. Do not infer individual gender identity from names and do not contact users through the linkage. Falsify the local opportunity if unsupported propagation is rare, the matched comparison shows no material excess burden under the manual baseline, or existing separation already performs adequately; otherwise produce only a reviewed pilot protocol with preset serious-disclosure, misidentification, privacy, continuity, and reporting stop criteria—not a live deployment.","blocking_evidence":["Target-institution prevalence of legal-name display lacking a documented legal, safety, reporting, verification, or continuity purpose.","Comparable local rates of correction work, delay, repeat contacts, unwanted disclosure, and observable abandonment under chosen-name-capable versus manual-exception interfaces.","Affected-party assessment of whether opt-in display across each candidate communication channel could itself create unwanted disclosure.","A system and vendor inventory showing where separate fields, stable identifiers, permissions, audit logs, and rollback are technically available.","Field-specific legal, contractual, records, identity-verification, financial, clinical, and reporting requirements in the intended jurisdiction.","Comparative evidence that the proposed monitored rollout improves outcomes rather than merely reproducing established UC, Minnesota State, or healthcare implementations.","Architecture-specific labor, vendor, security, support, and evaluation estimates sufficient to narrow the low-confidence launch bands."],"research_disposition":"KNOWN_PRACTICE_DIFFUSION","world_novelty_boundary":"This bounded search found close, operational prior art in the University of California, Minnesota State, and University of Iowa health systems. Therefore the legal-name/used-name separation mechanism, confidentiality model, stable-linkage approach, and purpose-specific exceptions should not be presented as novel. The remaining potentially distinctive contribution is only a local comparative evaluation protocol with explicit falsifiers and safety thresholds. The search did not exhaust patents, proprietary vendor deployments, non-English literature, every jurisdiction, or unpublished institutional evaluations, so it makes no world-novelty claim."}