Company / About

We came to credentialing from the fraud side.

Bip was built from an identity and fraud background rather than a credentialing services background, and almost everything different about the product follows from that one fact.

The founder

Reid Garrett

Founder and CEO
Identity verification
KYC identity binding
Fraud and compliance

Reid spent his career in identity verification and KYC identity binding — the work of establishing that a person is who they claim to be before anything is issued in their name. Part of it was at Equifax, in an industry where a regulator can ask you to prove any decision you made and the burden of proof sits with you.

He came to healthcare expecting to find the same discipline applied to the people who treat patients. What he found instead was an industry that verifies paper thoroughly and never verifies the person holding it.

“Compliance and regulatory rigor was beaten into me.”

Reid Garrett, on the Equifax years

What we found

Everyone verifies the credential. Nobody verifies the person holding it.

An NPI is an identifier, not an authenticator — it can be borrowed, inherited or stolen, and every check downstream of it inherits whatever was assumed at the start.

Federal investigators traced roughly 7,600 fraudulent nursing diplomas to a handful of schools. The licenses issued afterward were real, the board exams were real, and every one of those clinicians cleared credentialing at a legitimate facility.

Nothing failed. Credentialing did exactly what it was built to do, on a foundation nothing in the process was designed to examine. Provider credentialing is an identity problem wearing an administrative costume, and no amount of workflow fixes a trust layer that was never there.

HHS-OIG · Operation Nightingale

No platform we compete with markets identity verification of the provider at all. That is the gap the company was started to close.

What follows from that

Four design consequences, not four features.

Each one is a decision an identity company makes and a credentialing company generally does not.

  1. 01

    Provenance by default

    Every write to a provider record produces an append-only event carrying its source and its timestamp. The audit artifact is a byproduct of ordinary use, not something assembled retroactively under pressure.

  2. 02

    Identity underneath the file

    Credentials anchor to a person who was authenticated, rather than to a name string and a number. The verification chain terminates in a human being instead of an assumption.

  3. 03

    The provider maintains it

    The person with the most accurate information, and the strongest reason to keep it current, is the one attesting to it — on a date, section by section.

  4. 04

    It travels with them

    The record is bound to the provider and shared under their control, rather than rebuilt from zero inside every organization that needs it.

What we built

Two surfaces over one record.

A facility opens a request and the provider answers it from their own copy of the file — the same record, seen from the two sides that have to agree.

Web · credentialing teams
Facility Portal
Where the provider record is assembled, verified, monitored and turned into a packet, an enrollment or a privilege grant.
Mobile · the clinician
Provider App
Where the provider holds their own record, attests to it, and decides which organization sees which part of it.

One backend, one data model. The provider side is the half of this the category does not have.

The mission

More Time, Better Care

Credentialing is the gate between a clinician and the patients they are allowed to treat, and it is guarded by people re-keying the same facts into another form. We would like that work to stop being someone’s job.