--- title: "SIG-IS registration and certification for FSA/HSA payments" description: "Register or certify your business with SIG-IS so that card issuers approve your FSA/HSA payments." url: "https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa/sig-is-setup" source_url: "https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa/sig-is-setup.md" canonical: "https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa/sig-is-setup" last_modified: "2026-09-23T16:30:22+02:00" language: "en" --- # SIG-IS registration and certification for FSA/HSA payments Register or certify your business with SIG-IS so that card issuers approve your FSA/HSA payments. ##### Looking for the integration? This page covers the SIG-IS registration and certification that you complete with SIG-IS. For the technical integration, see [FSA/HSA payments](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa). To accept Flexible Spending Account (FSA) and Health Savings Account (HSA) card payments, you register or certify your business with the Special Interest Group for IIAS Standards (SIG-IS). This makes sure that card issuers approve eligible healthcare transactions. Registration is between you and SIG-IS. Your business type and your [merchant category code (MCC)](https://docs.adyen.com/get-started-with-adyen/adyen-glossary/#merchant-category-code) determine which program applies to you. They also determine whether you need a technical integration. This page explains the programs and how to register or certify. ## Requirements Before you begin, take into account the following requirements, limitations, and preparations. | Requirement | Description | | -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Integration type** | A [card payments integration](https://docs.adyen.com/payment-methods/cards) with Adyen in the US. For the IIAS program, you also need an [FSA/HSA payments integration](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa). | | **Limitations** | The SIG-IS programs apply to US-issued Visa and Mastercard FSA, HSA, and Health Reimbursement Arrangement (HRA) cards. | | **Setup steps** | Before you begin:- Create or log in to your SIG-IS membership account at [sig-is.org](https://www.sig-is.org). - Get your Adyen acquirer values, which you need on the SIG-IS forms. See [SIG-IS and Adyen terminology](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa/sig-is-setup#sig-is-and-adyen-terminology). | ## Which FSA/HSA scenario applies to your business You can accept FSA/HSA payments in multiple scenarios. The scenario that applies depends on your business type and your MCC. Only the IIAS (Inventory Information Approval System) scenario needs a technical integration. | Scenario | Best for | SIG-IS registration | Technical integration | | --------------------------- | ----------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ | | **Direct Medical Services** | Healthcare providers such as hospitals and dentists, on healthcare-only MCCs. | Not required | Not required | | **90% Rule** | Drug stores and pharmacies (MCC 5912 or 5122) with at least 90% of gross sales from eligible healthcare products. | [Required](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa/sig-is-setup#register-under-the-90-rule) | Not required | | **IIAS** | Any business that sells prescription (Rx) or over-the-counter (OTC) eligible healthcare items. | [Required](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa/sig-is-setup#certify-under-iias) | [Required](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa) | If your business is on a healthcare-only MCC (**Direct Medical Services**), card issuers approve eligible transactions based on your MCC. You do not register with SIG-IS and you do not change your integration. For the **IIAS** program, you send item-level healthcare data in each payment. This is the [Everyday Health Products category](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa#about-fsa-hsa-payments). See [FSA/HSA payments](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa) for the integration. ## How it works Registration or certification with SIG-IS follows the same overall steps: 1. You determine which program applies, based on your business type and your MCC. 2. You register under the 90% Rule or certify under IIAS with SIG-IS, and select Adyen as your acquirer. 3. Adyen reviews and verifies your submission. 4. For the IIAS program, Adyen gets your Transaction Control Numbers from Visa and Mastercard. 5. Your business locations go live, and you maintain your registration or certification. ## Register under the 90% Rule Use the 90% Rule if your business is a drug store or pharmacy (MCC 5912 or 5122). At least 90% of each qualifying store's gross sales must be from prescription medications and OTC eligible healthcare products. Take into account the following: * Your MCC must be 5912 or 5122. If your MCC is different, contact your Adyen account team before you continue. * You register each qualifying business separately. To register under the 90% Rule: 1. Create or log in to your SIG-IS membership account at [sig-is.org](https://www.sig-is.org). 2. Go to **Access IIAS Forms** > **90% Opt-In**. 3. Select **Adyen** as your acquirer. This auto-populates Adyen's contact details on your registration form. 4. For each qualifying business, enter the following: * Business trade name and physical address (name, street, city, state, zip code). * Adyen's Mastercard ICA Number (Acquirer BIN). * Adyen's Visa BIN Number (Acquirer BIN). * Card Acceptor ID (CAID) for Visa and Mastercard. * MCC, which must be 5912 or 5122. Get these values from your [Customer Area](https://ca-test.adyen.com/) (**Settings** > **Payment methods**) or from the Account Configuration report. Do not estimate or guess these values. 5. Attest that the business meets the 90% threshold for eligible product sales. 6. Submit the registration. Adyen reviews your registration within a few business days and verifies the data. If Adyen approves your registration, your business appears on the SIG-IS 90% merchant locator, and FSA/HSA card payments at your registered locations are approved. You must re-attest once a year to stay eligible. ## Certify under IIAS Use the IIAS program if your business sells prescription (Rx) medications or OTC eligible healthcare items and you want real-time, item-level substantiation at checkout. This program applies to pharmacies and to general retailers with a pharmacy department. The IIAS program needs a technical integration. See [FSA/HSA payments](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa). For the IIAS program, you are responsible for implementing an IIAS that uses the SIG-IS [Eligible Product List](https://sig-is.org/eligible-product-list/eligible-product-list-overview), which is updated monthly, and meets the IIAS Merchant Certification requirements. Complete the applicable Merchant Self-Assessment/Checklist and certification with your acquirer. An IIAS combines inventory management and point-of-sale systems. It must be able to: * Confirm the eligibility of FSA/HRA purchases by using eligibility flags in your inventory database. * Generate payment transactions with the required IIAS information. * Maintain an archive that lets you respond to IRS audits. Your checkout must also be able to: * Identify eligible cards with the BIN lookup at checkout. * Support [partial authorizations](https://docs.adyen.com/online-payments/partial-authorizations). ### Choose your certification path | Option | When to use | Process | | ----------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | | **Option A: SIG-IS-certified POS vendor or Third-Party Servicer (TPS)** | Your inventory and point-of-sale systems come from a SIG-IS-certified vendor. Check the SIG-IS-certified TPS list at [sig-is.org](https://www.sig-is.org). | Simplified TPS merchant certification. | | **Option B: IIAS self-assessment** | You develop your checkout in-house, or use a solution that is not on the SIG-IS-certified list. | Full IIAS self-assessment, plus a technical testing checklist that you complete with Adyen. | ### Complete the certification To certify under IIAS, for both options: 1. Create or log in to your SIG-IS membership account at [sig-is.org](https://www.sig-is.org). 2. Go to **Access IIAS Forms** > **IIAS/TPS Self-Assessment**. 3. Select the certification type: * **TPS Merchant Certification** for Option A. * **IIAS Self-Assessment** for Option B. 4. Complete the online certification form. Provide the following: * DBA (doing business as) name, business address, MCC, and Merchant ID (MID) for each location. * POS vendor and software version, or In-Person Payments (IPP) details. * Confirmation of the goods and services that you sell. * IIAS support capabilities, such as signature, PIN, and partial authorization. Select **Adyen** as your acquirer. 5. For Option B only: download and complete the IIAS testing checklist. Coordinate with your POS vendor and Adyen to complete the technical testing. Verify all IIAS fields in a test transaction before you submit. 6. Upload the completed checklist as a PDF and select **Submit**. Adyen reviews your certification form and checklist, and conducts or confirms the technical testing. If your certification is approved, Adyen gets your IIAS Transaction Control Numbers from Visa and Mastercard: the Merchant Verification Value (MVV) for Visa and the Mastercard Assigned ID (MAID) for Mastercard. This takes about 10 to 14 business days. When your Transaction Control Numbers are loaded, your business locations are live for IIAS transactions. After you go live with IIAS: * Keep the SIG-IS Eligible Product List updated in your checkout. SIG-IS publishes a new list every month. * If you previously registered under the 90% Rule, remove that registration. IRS rules require IIAS merchants to keep sales receipts with product detail for five years, in case of an IRS audit of an FSA cardholder. ## Maintain your registration or certification To keep accepting FSA/HSA payments, maintain your registration or certification and your SIG-IS membership. * **Annual re-attestation (90% Rule)**: SIG-IS requires 90% Rule merchants to re-attest once a year. SIG-IS notifies you when re-attestation is due. If you do not re-attest, SIG-IS removes you from the program and FSA/HSA cards are declined. * **SIG-IS membership renewal**: All merchants in the 90% Rule or IIAS program must keep an active SIG-IS membership. SIG-IS invoices you once a year. If payment is 50 or more days past due, SIG-IS removes you from all programs. ## Troubleshoot declined FSA/HSA payments If FSA/HSA card payments are declined, check the following. For **90% Rule** declines: * Confirm that the MCC, ICA, Visa BIN, and CAID in your SIG-IS registration exactly match the values in your authorization messages. Even a small mismatch causes issuer processors to decline the payment. * Confirm that your annual attestation is complete and current. * Confirm that your SIG-IS membership is active. For **IIAS** declines: * Confirm that your IIAS certification is complete and that you received your MVV and MAID Transaction Control Numbers from Adyen. * Confirm that the Transaction Control Numbers are included in the IIAS authorization messages. If you use a gateway, confirm that the values are also loaded there. * Confirm that your POS vendor sends all required IIAS data fields. * Confirm that your BIN file is updated with the latest version. SIG-IS updates it every week. * Confirm that your SIG-IS Eligible Product List is current. SIG-IS updates it every month. * Confirm that the partial authorization indicator is present in the authorization messages. FSA/HSA payments require partial authorizations. * If you send Rx subtotal or vision Rx subtotal fields, confirm that they are correct. ## SIG-IS and Adyen terminology The SIG-IS forms use different names for some of the values that you get from Adyen. Use the following table to map them. | SIG-IS portal | Adyen | | ----------------------- | ------------ | | Mastercard ICA Number | Acquirer BIN | | Visa BIN Number | Acquirer BIN | | Card Acceptor ID (CAID) | MID | ## Contact | Contact | Details | | --------------------------------------------------- | ----------------------------------------------------------------------------------------------- | | **SIG-IS** (questions about the technical standard) | Email: Help\@sig-is.org. Phone: +1 925 855 3228. Website: [sig-is.org](https://www.sig-is.org). | | **Adyen** (acquirer data values and support) | Contact your Adyen account team. | ## See also * [FSA/HSA payments](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data/fsa-hsa) * [Enhanced scheme data](https://docs.adyen.com/payment-methods/cards/enhanced-scheme-data) * [SIG-IS](https://www.sig-is.org)