Company / About
We came to credentialing from the fraud side.
Bip was built from an identity and fraud background rather than a credentialing services background, and almost everything different about the product follows from that one fact.
The founder
Reid Garrett
KYC identity binding
Fraud and compliance
Reid spent his career in identity verification and KYC identity binding — the work of establishing that a person is who they claim to be before anything is issued in their name. Part of it was at Equifax, in an industry where a regulator can ask you to prove any decision you made and the burden of proof sits with you.
He came to healthcare expecting to find the same discipline applied to the people who treat patients. What he found instead was an industry that verifies paper thoroughly and never verifies the person holding it.
“Compliance and regulatory rigor was beaten into me.”
What we found
Everyone verifies the credential. Nobody verifies the person holding it.
An NPI is an identifier, not an authenticator — it can be borrowed, inherited or stolen, and every check downstream of it inherits whatever was assumed at the start.
Federal investigators traced roughly 7,600 fraudulent nursing diplomas to a handful of schools. The licenses issued afterward were real, the board exams were real, and every one of those clinicians cleared credentialing at a legitimate facility.
Nothing failed. Credentialing did exactly what it was built to do, on a foundation nothing in the process was designed to examine. Provider credentialing is an identity problem wearing an administrative costume, and no amount of workflow fixes a trust layer that was never there.
No platform we compete with markets identity verification of the provider at all. That is the gap the company was started to close.
What follows from that
Four design consequences, not four features.
Each one is a decision an identity company makes and a credentialing company generally does not.
- 01
Provenance by default
Every write to a provider record produces an append-only event carrying its source and its timestamp. The audit artifact is a byproduct of ordinary use, not something assembled retroactively under pressure.
- 02
Identity underneath the file
Credentials anchor to a person who was authenticated, rather than to a name string and a number. The verification chain terminates in a human being instead of an assumption.
- 03
The provider maintains it
The person with the most accurate information, and the strongest reason to keep it current, is the one attesting to it — on a date, section by section.
- 04
It travels with them
The record is bound to the provider and shared under their control, rather than rebuilt from zero inside every organization that needs it.
What we built
Two surfaces over one record.
A facility opens a request and the provider answers it from their own copy of the file — the same record, seen from the two sides that have to agree.
- Facility Portal
- Where the provider record is assembled, verified, monitored and turned into a packet, an enrollment or a privilege grant.
- Provider App
- Where the provider holds their own record, attests to it, and decides which organization sees which part of it.
One backend, one data model. The provider side is the half of this the category does not have.
The mission
More Time, Better Care
Credentialing is the gate between a clinician and the patients they are allowed to treat, and it is guarded by people re-keying the same facts into another form. We would like that work to stop being someone’s job.