FOUNDING5050% off for lifeSee pricing →
UPP
UPP
Universal Provider Passport

NationalCredentialingInfrastructure

One verified passport. Accepted by every hospital, payer, and board.

UPP cuts physician credentialing processing time by as much as 80% — with continuous monitoring, primary source verification, and reusable signed credential packets.

HIPAA
SOC 2 Type II
HITRUST-ready
NCQA-aligned
24/7 monitoring
36-second walkthrough

See UPP run, end to end.

Packet → primary-source verify → signature → share → VERIFIED. Click any chapter to jump.

Open full demo
0:00 / 2:00
Five portals · one source of truth

Built for every side of credentialing.

See the live demo

Provider Portal

Build it once. Reuse it everywhere.

  • Signed credential wallet
  • One-click packet submission
  • Real-time expiration alerts
Launch provider portal

Hospital Portal

Privilege physicians in days.

  • Incoming packet inbox
  • Committee-ready review
  • Auto-PSV from 11 sources
Launch hospital portal

Payer Portal

Network ops without the rework.

  • Enrollment queue & SLAs
  • Sanctions & exclusion sweep
  • Directory accuracy scoring
Launch payer portal

Credentialing Specialist

Worklists that close themselves.

  • Smart task routing
  • Audit-grade evidence trail
  • Productivity analytics
Launch specialist portal

Recruiter Portal

Place verified physicians faster.

  • Attach pre-verified passports to candidates
  • Search consented providers by specialty
  • Cut credentialing-driven fall-off
Launch recruiter portal
Trust, in detail

Credentialing only works if every party trusts the same record.

Hospitals, payers, and state boards have spent decades duplicating verification because they couldn't trust each other's work. UPP exists to be the record they can all trust — cryptographically signed, primary-source verified, continuously monitored, and audit-ready by default.

What you can trust

The credential record itself.

Every license, board certification, DEA registration, malpractice policy, training history, work history, and sanctions check on UPP is a structured, versioned record — not a scanned PDF in someone's inbox.

  • Primary-source verified at ingestion, not self-attested
  • Cryptographically signed and tamper-evident
  • Versioned with full provenance and timestamp
  • Re-verified continuously, not just at hire
Why you can trust it

Independent sources, not our opinion.

UPP doesn't decide a physician is credentialed — the issuing authorities do. We pull directly from the same primary sources NCQA, CMS, and The Joint Commission require, and we show our work on every field.

  • NCQA-aligned PSV methodology
  • Every field cites its primary source + retrieval timestamp
  • Discrepancies flagged, never silently reconciled
  • Provider, hospital, and payer see the same record
How we earn it

Controls, not promises.

Trust comes from infrastructure, not marketing. UPP runs on isolated tenant data, encrypted end-to-end, with SOC 2 Type II controls, HIPAA BAAs, and an immutable audit log of every read, write, and verification.

  • SOC 2 Type II + HIPAA + HITRUST-ready
  • Customer-managed encryption keys available
  • Immutable, exportable audit trail
  • Role-based access with MFA enforced
Primary sources we verify against

11 authoritative sources. Live, not cached.

Every credential on UPP is verified against the actual issuing authority. If a source is down or returns a discrepancy, the record is marked — never silently approved.

See methodology
  • NPPES
    National Provider Identifier
  • CAQH ProView
    Attestation & demographics
  • PECOS
    Medicare enrollment
  • OIG LEIE
    Exclusions list
  • SAM.gov
    Federal debarment
  • NPDB
    Adverse actions & malpractice
  • ABMS
    Board certifications
  • AOA
    Osteopathic certifications
  • DEA CSA
    Controlled substance registration
  • State medical boards
    Licensure (all 50)
  • FSMB
    License history & actions
  • ECFMG
    Intl. medical graduate verification
Cryptographic provenance

Each credential packet is hashed and signed at issuance. Recipients can independently verify the packet wasn't altered in transit or after delivery — no need to trust UPP as the intermediary.

Immutable audit trail

Every view, share, verification, and policy decision is appended to a write-once log. Exports are signed and timestamped for board reviews, NCQA surveys, and CMS audits.

Continuous monitoring, not point-in-time

OIG, NPDB, sanctions, license status, and DEA registration are swept every 24 hours. Material changes trigger alerts to the provider and every organization with an active packet.

Provider-owned data

The passport belongs to the provider. Organizations get scoped, revocable access to packets the provider explicitly shares — not bulk database access.

Isolated, encrypted infrastructure

Tenant data is logically isolated and encrypted at rest (AES-256) and in transit (TLS 1.3). Enterprise customers can bring their own KMS keys for envelope encryption.

Discrepancies surface, never hide

When a primary source disagrees with a self-attested field, UPP marks the record as 'in dispute' and routes it to a credentialing specialist. We never auto-reconcile silently.

Open methodology

Our verification rules, source priority, and confidence scoring are publicly documented. Compliance teams can map every UPP field to NCQA CR standards in one page.

Versioned, never overwritten

Credentials are append-only. A license renewal creates a new version with full history — you can always answer 'what did this record look like on the day we privileged this physician?'

Data protection, specifically

How provider data is actually protected — to the byte.

Security at UPP is engineered, not declared. Every control below is in production today and independently verifiable in our SOC 2 Type II report.

Encryption at rest

AES-256-GCM on all stored data, with field-level encryption for PII (SSN, DOB, DEA #) using HSM-backed keys rotated every 90 days.

Encryption in transit

TLS 1.3 only, HSTS preload, certificate pinning on mobile, perfect forward secrecy. TLS 1.0/1.1 and weak ciphers are rejected at the load balancer.

Customer-managed keys (CMK)

Enterprise tenants can bring AWS KMS, Azure Key Vault, or GCP Cloud KMS via envelope encryption. Revoking your key cryptoshreds your tenant — instantly and provably.

Access control

RBAC down to the field level, MFA enforced on every account (TOTP, WebAuthn, FIDO2), SSO via SAML/OIDC, and SCIM provisioning for enterprise IdPs.

Tenant isolation

Logical isolation at the row, schema, and storage-bucket level with policy-enforced microsegmentation. No shared caches. No cross-tenant query paths.

Transparent access logs

Providers see every read of their record — who, when, why, from what org, against which policy. Logs are append-only and exportable.

Data sovereignty & deletion

US-only data residency (us-east + us-west). Provider-initiated deletion cryptoshreds keys within 24h and purges backups within 30 days, with a signed deletion receipt.

24/7 monitoring & response

SIEM-integrated anomaly detection, on-call SecOps, contractual 72-hour breach notification, and annual third-party penetration tests with public summary reports.

Why UPP is the clear choice

What makes us different from CAQH, legacy CVOs, and credentialing point tools.

Most credentialing tools digitize an outdated process. UPP rebuilds it around the only thing that actually matters: a primary-source-verified, continuously monitored record the provider owns and every stakeholder can trust.

PSV-first, not attestation-first

Why it's different: Most platforms start with what the provider types in. We start with what the issuing authority says — then reconcile.

Why it matters: Attestations expire and drift. Primary sources are the only record auditors, payers, and hospitals actually accept.

vs. status quo: CAQH is an attestation database. We are a verification record.

Continuous monitoring, every source, every day

Why it's different: Sanctions, licensure, DEA, and NPDB are swept every 24 hours — not at re-credentialing.

Why it matters: An excluded provider seeing patients for 18 months is a Medicare clawback event. We close that window to hours.

vs. status quo: Legacy CVOs verify at hire, then nothing for 2–3 years.

Reusable, signed packets — not point-to-point files

Why it's different: One verified packet is shared, scoped, and revoked across every hospital and payer the provider works with.

Why it matters: Providers stop filling out the same 50 fields 14 times a year. Organizations stop re-verifying what's already verified.

vs. status quo: Point tools re-do the work for every counterparty.

Discrepancies surfaced with provenance

Why it's different: When a primary source disagrees with a self-attested field, we mark it 'in dispute' and route it — never silently overwrite.

Why it matters: Silent reconciliation is how bad data enters the credentialing record. We make every conflict visible and resolvable.

vs. status quo: Most platforms default to the most recent value and discard the conflict.

Tamper-evident, exportable audit trail

Why it's different: Every read, write, verification, and policy decision is appended to a write-once log, signed and timestamped.

Why it matters: NCQA surveys, CMS audits, and board reviews demand provenance. We hand them a signed PDF in one click.

vs. status quo: Spreadsheet trackers and email threads are not an audit trail.

Provider-owned, portable identity

Why it's different: The passport belongs to the provider. They grant scoped, revocable access — not bulk database dumps.

Why it matters: Providers actually keep their record current when they own it. Organizations get a record that follows the clinician, not the org.

vs. status quo: Vendor-owned records become vendor lock-in.

Built for integration, not lock-in

Why it's different: Open APIs, FHIR-compatible exports, and pre-built connectors to Epic, Cerner, MD-Staff, symplr, and Verity.

Why it matters: Credentialing data has to land inside the EHR, MSO, and payer enrollment systems. We meet them where they live.

vs. status quo: Most platforms force you into their UI.

Compliance-aligned by default

Why it's different: Every field maps directly to NCQA CR, URAC, CMS, and Joint Commission requirements out of the box.

Why it matters: Your compliance team stops writing crosswalks. The mapping is the product.

vs. status quo: Generic CVOs leave the compliance mapping to you.

Capability comparison
UPP vs. CAQH ProView vs. legacy CVOs — capability by capability.
CapabilityUPPCAQH ProViewLegacy CVO
Primary-source verificationLive API to all 11 sourcesAttestation onlyManual, batch
Continuous monitoringEvery 24h, every sourceNoRe-verify at 2–3 yr cycle
Reusable signed packetsYes — scoped & revocableStatic profile sharePer-engagement file
Provider-owned consentYes — granular per orgOrg-level onlyNo
Discrepancy surfacingFlagged with provenanceSilent overwriteManual reconcile
Tamper-evident audit trailCryptographically signedActivity logPDF exports
Avg. time to ready-to-bill< 30 days60–90 days90–180 days
EHR / MSO integrationEpic, Cerner, MD-Staff, symplrLimited exportsCustom only
NCQA / URAC / CMS mappingBuilt inPartialDIY crosswalk

The net effect: providers carry one verified record everywhere they practice, organizations stop duplicating verification work, and auditors get the provenance they've always needed but never had.

What's the result?

The nation's first truly portable credentialing passport — one that never expires and never has to be reconstructed.

Continuously updated. Always available. Owned by the provider, trusted by every hospital, payer, and board they work with. Credentialing stops being a project and becomes a living record.

Never expires Continuously updated Provider-owned Always audit-ready
< 30d
Average credentialing cycle
Down from the industry's 90–180 day baseline.
24h
Monitoring sweep frequency
OIG, NPDB, sanctions, licensure, DEA.
11
Primary source integrations
Live API connections, not cached extracts.
98.4%
Directory accuracy
Measured against CMS provider directory rule.
Attestations SOC 2 Type II HIPAA + BAA HITRUST-ready NCQA CR-aligned GDPR-ready DPAs CCPA
Pricing

Free for clinicians. Fair for organizations.

Providers never pay to own their passport. Organizations pay for the workflows that move credentialing in days.

Starter
$29/seat / month

Small clinics getting credentialing out of spreadsheets.

  • Up to 25 providers
  • Credential wallet & document vault
  • Reusable packets (3 templates)
  • License + DEA primary-source checks
  • Email support
Start with Starter
Most popular
Pro
$79/seat / month

Multi-site groups and hospitals running real committees.

  • Unlimited providers & packets
  • All 11 PSV integrations
  • Continuous monitoring (daily sweeps)
  • Committee workflows & voting
  • SSO / SAML, audit log export
Upgrade to Pro
Enterprise
Customannual contract

Health systems, payers, and multi-state networks.

  • Custom PSV connectors & data residency
  • Dedicated CSM, 99.95% SLA
  • Delegated credentialing (hospital ↔ payer)
  • HITRUST / SOC 2 evidence packs
Talk to sales

Ready to credential in days, not months?

Create your free passport, or spin up an organization workspace in minutes.