Skip to main content
An Inventory Information Approval System (IIAS) is the mechanism the IRS defined for approving card transactions using item-level inventory data. For most e-commerce merchants, it is what makes accepting HSA/FSA cards possible at all. Flex operates an IIAS on your behalf. This page covers what the IRS requires and how each requirement is met.

Why IIAS exists

Every HSA/FSA purchase must be substantiated as an eligible medical expense — but who carries that burden depends on the account:
  • FSAs and HRAs are employer-sponsored, so the plan must be able to show that reimbursed amounts were for qualified medical care.
  • HSAs are individually owned, so the account holder is responsible for retaining documentation — invoices, receipts, and letters of medical necessity.
Notice 2006-69 formally introduced IIAS because the IRS recognized that general retail sells a mix of eligible and ineligible items, and card payments must prevent ineligible spend from being treated as tax-free medical reimbursement. The IRS definition is straightforward: an IIAS is a system provided by the payment card processor for approving and rejecting card transactions using inventory control information — SKUs, UPCs, GTINs — at merchants who need not be health care providers.

What an IIAS must do at checkout

1

Collect item-level inventory data

Capture the SKU or equivalent inventory identifier for everything in the cart.
2

Compare against a qualifying list

Check those items against a list of products that qualify as medical care expenses under IRC §213(d).
3

Approve only the eligible subtotal

Total the qualified expenses and authorize the card for that amount only. If the cart also contains ineligible items, the system must support a split-tender transaction so the customer pays the remaining balance with another payment method.
In essence, IIAS is a specific set of behaviors at checkout: product-level eligibility, eligible-only approval, split-tender for mixed carts, and audit-ready records.

Who needs IIAS

Notice 2007-2 established the path for merchants that are not traditional healthcare providers to accept HSA/FSA card payments. Non-healthcare MCC merchants. Every merchant has a merchant category code (MCC) assigned by their acquiring bank or payment processor. Since December 31, 2007, FSA and HRA debit cards cannot be used at stores without healthcare-related MCCs unless the merchant has an IIAS. Drug stores and pharmacies. Since July 1, 2009, FSA/HRA debit cards may not be used at Drug Stores & Pharmacies MCC locations unless the store participates in an IIAS, or meets the 90% rule — 90% of gross receipts from §213(d) medical items, measured location by location.
The 90% rule does not eliminate substantiation work. IRS guidance indicates many charges at 90%-rule stores must still be treated as conditional pending third-party information — the “pay-and-chase” model — except for specific auto-substantiation categories such as copay matches, recurring charges, and real-time substantiation.
Unless you have a healthcare-related MCC or qualify under the 90% rule, IIAS is not optional for accepting HSA/FSA payments. For e-commerce at scale it is also the practical path, because it enables real-time item-level gating instead of a manual substantiation workflow.

How Flex meets each requirement

Flex operationalizes these requirements inside your checkout, so you don’t build SKU-level substantiation infrastructure yourself.

1. SKU-level eligibility decisioning aligned to §213(d)

Flex makes eligibility determinations for all merchant products and services according to §213(d), assigning that eligibility down to the product level using both a unique Flex ID and the product’s UPC or GTIN. Using the product’s own identifiers keeps determinations consistent across merchants — the same item resolves the same way regardless of who sells it.

2. Eligible-only approval

Flex authorizes the HSA/FSA payment for the eligible subtotal only, preventing over-approval.

3. Split-tender for mixed carts

Flex enables a single checkout flow where the customer enters their HSA/FSA card for the eligible amount and a credit or debit card for the remainder — without forcing two separate orders. See How Checkout Works.

4. Audit-ready records and retention

Flex maintains the Flex Eligible Catalogue — all eligible and non-eligible products and services across every merchant in our system, with every determination mapped back to §213(d). We also retain transaction decisioning evidence and supporting documentation for merchants, customers, and HSA/FSA administrators during audits and operational reviews.
IRS guidance is clear that employers using an IIAS remain responsible for applicable requirements including recordkeeping (Notice 2006-69). Flex retains the underlying decisioning evidence to support that.

How Flex Determines Eligibility

The IRC §213(d) standard behind every determination.

How Checkout Works

Split carts, eligibility types, and the customer-facing flow.