@farmerman,
Most financial sites are posting notices if they are affected by the Bleed, or they are notifying everyone once they have updated their code.
I would only worry about financial passwords, assuming that you use different passwords for different sites, and only change them once the institution has put out a notice that they have upgraded.
It's usually good to change passwords every so often anyway, so this is a good excuse to go through the exercise (just not too soon, or the new password could be compromised).