Reporting Unauthorized HSA Transactions
To help protect your HSA funds, please:
Review your HSA transactions online regularly, and your HSA statement each month.
Tell us immediately if your card is lost or stolen, or you see unauthorized transactions, by calling 1-866-346-5800. You must notify us within 60 days of your statement being made available.
Why 60 days? Fraud prevention is a collective effort. Recovery of funds is not guaranteed. The sooner you notify us, the more likely that funds can be recovered on your behalf. As noted in your HSA Custodial Agreement, failure to report unauthorized transactions within 60 days means you have accepted the transactions, they might not be eligible for reversal, and you could be responsible for the full loss.
HealthEquity Passkey FAQs
What is a passkey?
A passkey is a secure login credential stored on your device. You use your fingerprint, face, or device PIN to log in—instead of a password.
Why should I use a passkey instead of a password?
Stronger protection: Passkeys are designed to help reduce the risk of phishing and credential theft by using built-in device authentication.
Fewer Hassles: No more password reset when you get a new device.
Smoother sign-in experience: Passkeys are stored in your device’s secure keychain (iOS, Android, Windows Hello, ChromeOS) and may sync across devices through your Apple ID or Google Account.
How do I set up a passkey?
The first time you log in after passkey is enabled, you'll be prompted to create your passkey using the HealthEquity Mobile app. It's quick and secure—and you won't be able to access your account until your passkey is set up.
Which devices and browsers support passkeys?
Mobile: iOS 16+ (Safari), Android 14+ (Chrome)
Desktop: Windows 10+ (Edge/Chrome), macOS Ventura+ (Safari/Chrome), ChromeOS 109+
Browsers: Safari 16+, Chrome 109+, Edge 109+, Firefox 122+
Can I use my passkey on multiple devices?
Yes—your passkeys sync through your device’s cloud keychain (iCloud Keychain or Google Password Manager). If you need to sign in on a device not linked to your cloud account, simply scan the on-screen QR code with your phone to authenticate.
What if I lose my device or it’s stolen?
If your passkey is saved to your device's cloud keychain or another credential manager, you can still log in from any other device connected to it. If not, don’t worry—you’ll be able to create a new passkey right from the login screen.
Can I still sign in with my username and password?
Passkeys are the new standard for accessing HealthEquity accounts. In some cases, you may temporarily see the option to sign in with your existing credentials, but all members will eventually be required to set up a passkey. Using the mobile app is the best way to get started—it’s secure, simple, and puts your benefits at your fingertips.
How do I remove or disable a passkey?
In the mobile app: Settings > Security & Privacy > Manage Passkeys > tap Delete next to the device name.
On desktop: My Profile > Security Settings > Passkeys > click the trash icon.
Do passkeys expire?
No. They remain valid until you manually remove them from your HealthEquity account and from your device.
What if my device doesn’t support passkeys?
Most smartphones and modern computers support passkeys through Face ID, fingerprint, or a secure PIN. We recommend downloading the HealthEquity Mobile app as the easiest and most secure way to access your account.
How do you protect my biometric data and PIN?
Your biometric templates (face/fingerprint) and any PINs you use to unlock your device never leave your device. HealthEquity only interacts with the public key portion of your passkey—nothing sensitive is transmitted or stored on our servers.
Need help or have more questions?
We’re here to make your sign-in more secure—and your HSA safer—every step of the way. If you run into trouble setting up your passkey, we’re ready to help.
Call our dedicated support team at 1-866-346-5800 to address any passkey set up related issues.
COBRA/Direct Bill Employer login
Please refer to your Client Welcome email for the URL of your specific COBRA/Direct Bill Employer login page.
Follow us