Platform / Identity verification

Verify the person, not just the paperwork.

Every credentialing system on the market verifies documents. None of them verify that the person holding those documents is who they say they are. Bip starts there.

What a credentialing file rests on
Claims & billingAssumes enrollment is valid
Payer enrollmentAssumes credentialing is valid
PrivilegesAssumes the credential is valid
The credentialVerified against the state board
The identifierNPI matched against NPPES
The personAssumed. Never verified.
Five clean verifications on an unverified foundation.

Every layer above takes the layer below on faith. Nothing in credentialing was designed to look down.

Why it matters

Verification chains inherit trust.

Each check downstream assumes the one upstream was sound. A credential built on a fraudulent foundation verifies cleanly at every step after it, because no step after it was designed to look down.

7,600

Fraudulent nursing diplomas traced to a handful of schools. The people holding them sat real board exams, received real licenses, and passed credentialing at real facilities. Every downstream check worked exactly as designed.

HHS-OIG · Operation Nightingale

This is not a story about weak verification. It is a story about verification that never reached the bottom of the stack.

How it works

Establish the person first. Then keep the binding current.

Bip applies the sequence a financial institution uses before it opens an account, to the moment a provider enters your system.

01 · At enrollment

The person is established

Government ID authenticated when the provider joins, before credentials are anchored to them. Not a name-and-NPI match against a public registry.

02 · In the file

Credentials attach to a person

The record is anchored to that established identity rather than to a name string, so the file has a human being underneath it rather than an assumption.

03 · Over time

Attestation re-affirms it

The provider confirms their record section by section, on a date. Each attestation is timestamped and written to the file’s event log.

Bip came out of identity, fraud and compliance work, not credentialing services. That is why the sequence starts here rather than ending here.

Where this is today

What the platform does, and what it is designed to do.

Credentialing buyers are trained to find the gap between a claim and a capability. Here is ours, before you have to go looking for it.

Live today
Part of the platform
  • Government ID authentication at enrollment
  • Provider attestation at field and section level, timestamped
  • License verification against the issuing state board
  • Monthly OIG LEIE exclusion screening
  • Expirables monitoring and alerting
  • Relay provenance — hash-chained, append-only event history
  • BipSubmit portal fill across payer and facility portals
  • Bylaws extraction into a privilege delineation matrix
  • Privileging end to end, from delineation through committee packet
  • HIPAA audit trail across both surfaces
Architecture
How the system is designed, not a shipped feature
  • Binding extended across all credential domains in the file
  • Full primary source verification coverage
  • Passport API for third-party consumption

We would rather lose a deal on this table than win one and have it surface in a security review.

What we do not publish

We will not tell you how the verification works.

Not on this page, not in a deck, not to a prospect. This is deliberate, and it is worth explaining why.

  • Publishing the method tells anyone attempting to defeat it precisely what they have to defeat.
  • Naming a vendor dates the claim the moment the vendor changes, and invites a spec argument in place of a conversation about your risk.
  • The people asking hardest are rarely buyers. They are frequently the ones probing for the seam.

Under a security review and an NDA, the detail is available in full. In public, the claim is what the file proves, never how.

Questions we get

Identity in credentialing, plainly.

What is identity binding in credentialing?
Identity binding is the practice of establishing that a provider is who they claim to be, and then anchoring their credentials to that established identity rather than to a name and an identifier. Conventional credentialing verifies the documents and assumes the person. Identity binding closes that gap so the verification chain terminates in a human being instead of an assumption.
Why is verifying an NPI not enough?
An NPI is an identifier issued to a provider, not proof that the person presenting it is that provider. It can be borrowed, inherited from someone deceased, or stolen, and federal enforcement actions have shown all three. Because verification chains inherit trust, a file built on a misattributed NPI verifies cleanly at every downstream step.
Does identity verification replace primary source verification?
No, and anyone claiming it does is selling something. Primary source verification confirms that a credential is genuine and current with the body that issued it. Identity verification confirms that the person holding that credential is who they say they are. They answer different questions, and a defensible file needs both.
What was Operation Nightingale, and why does it matter here?
A federal investigation that traced roughly 7,600 fraudulent nursing diplomas to a small number of schools. The significant detail for credentialing is that the licenses issued afterward were real. Candidates sat and passed board exams, held valid licenses, and cleared credentialing at legitimate facilities. Every verification worked. None of them examined the foundation.
Does a provider have to verify again at every facility?
That is the design intent behind a provider-held record. The provider establishes their identity once and carries it, so a subsequent facility inherits an established identity rather than restarting from a blank form. How much of that a given facility accepts remains the facility’s decision, governed by its own policy and its accreditor’s requirements.

See what a file looks like with a person underneath it.

Bring one provider. We will walk the whole chain with you, from the identity up.