Facility-side credentialing & provider identity

Stop chasing providers. Start owning the file.

Bip is the system of record your credentialing team runs on. Every credential is bound to a verified identity, and every request, document, and attestation lands in one provider file with a timestamped, tamper-evident trail behind it.

See the product before you talk to anyone. Nothing gated below this line.

Okafor, Dana T., MD
Maternal-Fetal Medicine · NPI 1▮▮▮▮▮▮▮▮9
Active file
Profile complete
14 / 14 sections
Last attested
6 days ago
AZ license
Verified · issuing board
Malpractice COI
Expires in 31 days
Payer enrollments
4 active · 1 pending
Privileges
Signed · committee ready
FILE 0x7A2E · 41 EVENTS · CHAIN INTACT◆ IDENTITY-BOUND
Running credentialing for
Valley Perinatal ServicesArizona · multi-site perinatology · 60+ providers

The verification gap

Credentialing stopped being something you complete. It became something you have to keep proving.

A process built to assemble a file every three years cannot prove what was true every thirty days. The re-typing, the stale PDFs, and the weeks spent waiting on a provider are symptoms. This is the cause.

$14.6B

Alleged fraud. 96 of the 324 defendants were licensed medical professionals.

DOJ · 2025 health care fraud takedown
7,600

Fraudulent nursing diplomas. The licenses that followed were real.

HHS-OIG · Operation Nightingale
61%

Of practices carry an active lapse right now. 78% go unnoticed for 60 days or more.

Analysis across 190 specialty practices
540

Average days a directory inaccuracy persists. The rule says 90.

Am. Journal of Managed Care

Attributed, not asserted. Read the full market brief →

Workstreams

The work your team already does, on one file.

Five workstreams, one provider record. Finishing one never means re-entering data for the next.

01

Provider onboarding

Open one request. The provider completes it on their phone, attests to what is current, and the data lands structured in your file. No PDF packet, no email thread, no re-typing.

Facility Portal · Onboarding
Request sent — 4 itemsOpened
State medical licenseReceived
DEA registrationReceived
Malpractice COIWaiting
Work history gap — 2023Waiting

62% complete · no staff time spent since the request opened

02

Credential file & documents

Every document attaches to the credential it evidences, not a shared folder. Expirations are read off the document itself and become dated signals before anything lapses.

Facility Portal · Credential file
AZ Medical LicenseVerified
DEA RegistrationOn file
Board — ABOG, MFMOn file
Malpractice COI31 days
BLS / ACLSOn file

Expirations read from the document · 3 signals queued

03

Payer enrollment

Your file fills the payer's portal. BipSubmit carries structured data into external applications so your team stops re-keying the same forty fields into every plan.

BipSubmit · Payer portal
Aetna — AZ commercialIn review
UnitedHealthcareEffective
AHCCCS — MedicaidIn review
Medicare — PECOSEffective
BCBS AZReady

Fields filled from the file · 0 re-keyed by staff

04

Privileging

Upload a hospital's bylaws and Bip parses them into a delineation matrix. Privileges, signatures, and committee packets are assembled from the same record the rest of the file lives in.

Facility Portal · Privileging
Bylaws parsed — 42 delineationsExtracted
Core privileges — MFMSigned
Department chair reviewPending
Committee packetAssembled

Packet built from the file · tamper-evident signatures

05

Monitoring & recredentialing

License, sanction, and expiration state watched continuously. Recredentialing starts from a file that never went stale, so the cycle is a review instead of a rebuild.

Signals · Monitoring
Malpractice COI expiring31 days
Recredentialing cycle opens44 days
OIG exclusion sweepClear
License check — AZ boardCurrent
Attestation aging past 120dRequested

Watched continuously · sorted by what breaks first

BipSubmit · Chrome extension

Every portal, filled for you.

Payer portals will never have an API. So BipSubmit works where your team already does: in the browser, on the payer’s own form.

  • Reads the provider’s file, not a saved autofill profile
  • Works on any payer or facility portal, no integration required
  • Flags fields the file cannot answer instead of guessing
  • Writes the submission back to the file as a dated event
Request access
portal.examplepayer.com/enrollment/practitioner
Bip
Practitioner enrollment — section 2 of 7
Legal name
 
NPI
 
Primary specialty
 
State license
 
License expiration
 
Board certification
 
Filling from the provider file…0 / 40 fields · 0 re-keyed
Fields filled from the provider file
By hand0
With BipSubmit40

Field counts from a payer’s own practitioner application. Your mileage varies by payer.

Identity binding

The NPI is an identifier. It was never an authenticator.

Verification chains inherit trust. A credential built on a fraudulent foundation verifies cleanly.

Standard credentialing2 of 4
The credentialPrimary source verified
The identifierNPI matches NPPES
The personAssumed, never verified
The binding over timeRevisited every 2 to 3 years
On Bip4 of 4
The credentialPrimary source verified, dated event
The identifierNPI matched against NPPES
The personGovernment ID authenticated
The binding over timeRe-confirmed on attestation

Bip came out of identity and fraud, not credentialing services. How identity binding works →

“I spent a decade in identity, fraud and compliance at Equifax scale. Credentialing is an identity and trust problem wearing an administrative costume — everyone verifies the paperwork, and nobody verifies the person. We built Bip to fix the trust layer underneath the workflow, not just to make the old process faster.”
Reid Garrett · Founder & CEO, Bip Identity

Provenance

A credentialing file is not a status. It is a chain of evidence.

Onboarding takes weeks and crosses SMS, portals, boards, and signatures. Bip records every one of those touches, with who, when, and from what source, in an append-only log you can hand to an auditor.

File 0x7A2E · Okafor, D. — MFM · Northwind Perinatal GroupKey events 1 of 10 shown · 41 total
RequestWK 1 · 09:14

Credentialing request opened

Four missing items identified against the facility's requirement set. One request, not four emails.

ActorR. Alvarez, MSP
SurfaceFacility Portal
SourceRequirement set v4
Writes4 pending fields
Chain  …0fd5…9a239f4c…a071 1b83…c4de

Step through with the arrows or the keyboard. Sample file, real event model.

One record

Credentialing, privileging, and enrollment are not three problems.

They are three destinations for the same provider data. Everyone treats them as separate departments. They never were.

Provider

Attests once

Confirms their own record is current, on a date, from their phone.

Bip

One verified file

Identity-bound, with every change dated and sourced.

PayersEnrollment · rosters
Hospitals & facilitiesCredentialing · privileging
RegistriesNPPES · PECOS · CAQH

Same data, shared the way each destination needs it. That is the whole architecture.

Why teams keep it in-house

Outsourcing credentialing does not remove the work. It removes your view of it.

Who holds the record
Outsourced CVO — The vendor. You get a status page.
On Bip — You do. Exportable, structured, yours.
Provider experience
Outsourced CVO — Email and PDF, chased by a stranger.
On Bip — An app the provider owns and reuses.
Audit evidence
Outsourced CVO — Requested, assembled, delivered later.
On Bip — Append-only event log, available now.
What recredentialing looks like
Outsourced CVO — A new engagement. The file is largely rebuilt.
On Bip — A review of a file that never went stale.
What happens if you leave
Outsourced CVO — The file history stays with them.
On Bip — The file leaves with you.

A CVO is the right answer for some teams. If yours has institutional knowledge worth keeping, this is the trade you are actually making.

Security
Tenant-scoped access controlAppend-only audit historyProvider-controlled sharingEncrypted in transit and at restBAA available
Security page →

Questions we get

Credentialing, plainly explained.

What is provider credentialing?
Provider credentialing is the verification of a clinician’s qualifications before they can treat patients or bill for care. It covers primary source verification of licensure, education, training, board certification, malpractice coverage, and work history, and it repeats on a recredentialing cycle, typically every two to three years. Standards are set by accreditors including NCQA and The Joint Commission.
How is credentialing different from payer enrollment?
Credentialing verifies that a provider is qualified to practice. Payer enrollment is the separate process of getting that provider into a health plan’s network so their services can be billed. Both must finish before a provider generates revenue, and they draw on the same underlying provider data, which is why they belong in one record rather than two systems.
What is provider attestation?
Attestation is the provider confirming that the information on file about them is current and accurate, on a specific date. It is what turns stored data into defensible data. In Bip, a provider attests section by section in the Provider App, and each attestation is timestamped and written to the file’s event log.
Why is verifying an NPI not enough?
An NPI is an identifier issued to a provider, not proof that the person presenting it is that provider. It can be borrowed, inherited, or stolen, and federal cases have repeatedly shown all three. Verification chains inherit trust, so a credential built on a fraudulent foundation verifies cleanly against every downstream check. Identity binding closes that gap by proofing the human being first and tying the credentials to that proofed identity.
What changed in credentialing standards in 2025 and 2026?
Verification windows shortened, monitoring moved from once-per-cycle to roughly monthly against exclusion lists, NPDB, and state license data, and organizations now have to evidence information integrity rather than just document a policy. Separately, Medicare Advantage directory rules require updates within 30 days and annual accuracy attestation. The practical effect is that credentialing changed from a periodic event into a continuously provable state.
Does Bip replace CAQH?
No. CAQH is a provider-maintained data source that payers draw from. Bip sits on the facility side and aligns with CAQH-shaped data so providers are not entering the same information twice. The two are complementary.
How long does credentialing take?
Traditional credentialing commonly runs 90 to 120 days, and delays usually come from incomplete applications and slow provider response rather than from verification itself. That is why the response loop, not the verification step, is where the time is actually recovered.

Stop rebuilding providers from scratch.

Bring one provider and see what a file looks like when it remembers everything.