← Back to blog

Cut HSA/FSA Card Costs 35% for U.S. Providers: IIAS and API Fixes

September 3, 2026
Cut HSA/FSA Card Costs 35% for U.S. Providers: IIAS and API Fixes

Most U.S. merchants can accept HSA and FSA cards through one of two paths: an auto-approved Merchant Category Code (MCC) like a doctor's office or pharmacy, or an IIAS-certified point-of-sale system for mixed-inventory retailers. Either way, the terminal needs EMV certification, PIN debit support, and partial-authorization capability to route transactions correctly.


TL;DR:

  • Most merchants will need an IIAS-certified point-of-sale system and EMV PIN support to process HSA and FSA cards at mixed inventories, with auto-approved MCCs covering healthcare providers.
  • Declines often originate from MCC misclassification, missing support for partial authorization, or incorrect configuration of inventory mapping and API fields, especially the medical_amount.
  • Maintaining accurate eligibility lists, supporting split-tender transactions, and regularly verifying systems and sales data are key to avoiding declines and ensuring compliance.
  • Relying solely on plastic reading is insufficient; approval depends on proper authorization data passing the right eligibility codes and having auditable sales proof.
  • Using a processor with built-in MCC logic and automatic substantiation features minimizes rejection risks and simplifies maintaining compliant acceptance.

Table of Contents

Who Qualifies for HSA FSA Card Acceptance

Healthcare providers rarely have to do anything special to accept HSA and FSA cards. If your business already carries a qualifying MCC, the card networks have effectively pre-cleared you.

Auto-approved categories typically include:

  • Physicians, dentists, and other licensed medical practitioners
  • Hospitals and urgent care facilities
  • Pharmacies and drug stores
  • Optometrists and ophthalmologists
  • Independent clinical labs and diagnostic centers

These merchants can accept HSA/FSA cards without an Inventory Information Approval System (IIAS) because the MCC itself confirms medical intent. Retailers who sell a mix of eligible and ineligible goods, such as a grocery store with a pharmacy counter, don't get that automatic pass. They need an IIAS-certified system that checks each item against a registered eligible-products list.

That's where the Special Interest Group for IIAS Standards (SIGIS) comes in. SIGIS maintains the approved eligible-product list and certifies which POS systems can auto-substantiate FSA/HSA purchases at checkout. Even with a correct MCC and working IIAS, a specific health plan administrator or card issuer can still layer on its own restrictions, which is one reason a transaction can decline even when your setup looks compliant on paper.

Technical Setup for HSA FSA Card Payments

Getting the acceptance logic right on paper doesn't matter if your hardware and gateway can't execute it. Three technical pieces have to work together: the terminal, the IIAS layer, and the authorization fields your processor passes to the card networks.

  1. EMV-certified terminals with PIN debit support. Any standard EMV terminal that also processes PIN debit can physically read an HSA/FSA card. The eligibility restrictions live in software, not the chip itself.
  2. IIAS-certified POS for mixed inventory. The system checks each SKU against the SIGIS eligible-item list in real time and flags the eligible dollar amount before authorization.
  3. Partial authorization and split-tender support. When a cart mixes eligible and non-eligible items, the processor needs to split the charge, applying the HSA/FSA card only to the qualified portion and routing the rest to a separate payment method.
  4. Correct API fields on the gateway side. Processors typically require an explicit medical_amount field (or equivalent) alongside standard transaction data so the issuer knows exactly what portion to approve, per Fiserv's CardPointe developer documentation.
  5. eCommerce-specific verification. Online checkouts need either BIAS-equivalent item mapping or a certified health-card processing path; Visa and Mastercard require registration and specific transaction fields before an online merchant can process these cards, according to JPMorgan's payments developer portal.

Pro Tip: Ask your gateway provider directly whether they support the medical_amount field and partial authorization out of the box. Some legacy gateways silently drop these fields, which causes declines that look like a card problem but are actually a configuration gap.

Setting Up HSA FSA Card Acceptance Step by Step

Rolling out compliant acceptance is a sequencing problem more than a technical one. Handle these steps in order and you avoid the rework that comes from testing before your account is even configured correctly.

  1. Confirm your registered MCC with your processor and correct it if it doesn't reflect your actual business (a common cause of unexpected declines).
  2. Verify that your terminal supports EMV and PIN debit, and confirm your POS software carries IIAS certification if you sell mixed inventory.
  3. Register with SIGIS if you sell any FSA/HSA-eligible products alongside non-eligible ones.
  4. Enable partial authorization and the health-card authorization fields in your gateway and processor settings.
  5. Run test transactions in-person and through your online checkout, covering full-eligible, split-tender, and fully-ineligible scenarios.
  6. Train front-line staff on how split-tender purchases work so they can explain a partial charge to a customer without confusion.
  7. If you're relying on the 90% Rule instead of full IIAS, start documenting sales composition now, not after an audit request arrives.

Why HSA FSA Transactions Decline and How to Fix It

Most declines trace back to one of four fixable issues, and understanding which one is hitting you saves a lot of guesswork on the phone with your processor.

  • MCC misclassification. If your account is coded incorrectly, or your card issuer applies its own MCC-level restriction, transactions fail before they even reach the eligibility check. Confirm the code with your processor first.
  • IIAS misconfiguration. Mislabeled inventory or a lapsed SIGIS registration means eligible items get rejected at checkout. Re-verify your item mapping periodically, not just at initial setup.
  • 90% Rule misuse. The 90% Rule lets a merchant skip full IIAS if at least 90% of sales are eligible, but many merchants who claim it can't actually prove it. Auditable sales tracking is not optional here; it's the entire basis for the exemption.
  • Missing partial authorization or incomplete API fields. If your gateway isn't passing medical_amount or supporting split-tender, otherwise-eligible purchases will decline outright.

Card issuers retain the final say on any transaction, and even a perfectly configured merchant setup can't override an issuer-level decline, a point Talus Pay's guidance makes clear. Processors offering enhanced MCC logic and auto-substantiation tend to catch more of these edge cases before they become a customer-facing problem, which is exactly the kind of infrastructure worth prioritizing when you pick a processing partner.

Best Practices for Reliable HSA FSA Card Payments

Compliance isn't a one-time setup. It's a maintenance habit, and the merchants who avoid recurring declines treat it that way.

  • Keep your eligible-item list current, especially for dual-use products that shift between eligible and ineligible depending on packaging or bundling.
  • Train POS and customer-service staff on split-tender flows and how to explain an issuer-side decline without implying your business did something wrong.
  • Retain auditable sales reports if you're leaning on the 90% Rule or IIAS certification; a processor or card network can request evidence with little notice.
  • Coordinate with your compliance officer on HIPAA-safe payment data handling, keeping PCI DSS and SOC controls intact alongside your health-card processing setup.

Pro Tip: Build a quarterly review into your calendar just for eligible-item audits. Product catalogs change more often than most merchants expect, and a stale eligibility list is one of the quieter causes of creeping decline rates.

What Merchants Consistently Get Wrong About HSA FSA Acceptance

The biggest misconception is treating HSA/FSA acceptance as a card-reading problem when it's really an authorization-data problem. The plastic swipes or taps fine on nearly any modern terminal. What actually determines approval or decline is whether your processor passes the right eligibility fields and whether your inventory system tells the truth about what's eligible.

It's a legitimate path, but only with auditable tracking that proves the threshold, and plenty of merchants discover that gap only when an audit request lands on their desk.

Paysec's healthcare clients see this firsthand: a documented 35% reduction in processing costs for one practice came from pairing correct MCC classification with Network Offset Pricing, not from a workaround. Paysec's HIPAA-compliant merchant accounts and terminal support handle the IIAS and partial-authorization configuration work directly, so operation teams spend less time troubleshooting decline codes and more time seeing patients. Anyone building out acceptance should treat the linked case study and IIAS documentation as required reading before going live.

— PaySec Marketing Team

Get HSA FSA Acceptance Running Without the Processing Markup

Paysec gives healthcare providers and eligible retailers a direct path to compliant HSA/FSA acceptance while cutting the transaction fees that usually eat into margin on every claim. Where many processors bolt on health-card support as an afterthought, Paysec builds it into HIPAA-compliant merchant accounts from day one, with IIAS-capable integrations and EMV/PIN terminals configured to handle partial authorization correctly the first time.

Paysec

Onboarding is straightforward: Paysec sets up your merchant account, configures your terminal or mobile reader for PIN debit and EMV acceptance, and applies Network Offset Pricing so you keep more of what you process, with no long-term contracts and no hidden fees. Real-time reporting through Paysec's dashboard also gives you the auditable sales data you need if you're documenting the 90% Rule or an IIAS exemption. For practices that need acceptance beyond the front desk, Paysec's mobile payment processing extends the same EMV/PIN and partial-auth capability to any point of care. Start by reviewing the healthcare payment processing page and requesting a rate comparison against your current processor.

FAQ

Can Any Business Accept HSA and FSA Cards?

Only businesses with an auto-approved MCC or an IIAS-certified point-of-sale system can process HSA/FSA cards; a standard retail MCC without IIAS will typically see these transactions declined.

What Is the Difference Between HSA and FSA Card Acceptance?

The acceptance requirements are identical from a merchant standpoint. Both card types route through the same MCC and IIAS checks; the difference lies in the account rules the cardholder's plan administrator applies, not in your processing setup.

Do I Need IIAS if I'm a Doctor's Office?

No. Auto-approved medical MCCs like physicians, dentists, hospitals, and pharmacies don't need IIAS because the merchant category itself confirms eligible medical purpose.

What Causes Most HSA FSA Card Declines?

MCC misclassification, missing partial-authorization support, and incomplete IIAS or SIGIS setup account for most declines; issuer-level restrictions on the cardholder's plan can also cause a decline that merchant-side fixes can't override.

How Does the 90% Rule Work for Retailers?

The 90% Rule lets a merchant skip full IIAS certification if at least 90% of sales are FSA/HSA-eligible, but it requires auditable sales tracking to prove that threshold if a processor or card network requests evidence.