Require covered Chinese medical-device manufacturers to provide cybersecurity and data-location information, including software bills of materials and patient-data server locations, for federal review.

Tom Cotton · Arkansas · Republican

oversight impact 0.55 specificity 0.90 extraction confidence 93%

Contest this claim

Occurrences

Not later than 180 days after the date of enactment of this Act, the Secretary, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall request from each covered manufacturer of a covered device such information as is necessary to conduct the review under paragraph (1), including... a software bill of materials... locations of entities, information systems, and servers holding patient data.

The bill would require HHS/FDA and CISA to request cybersecurity, software, architecture, and patient-data location information from each covered Chinese medical-device manufacturer within 180 days of enactment.

Countering Chinese Cyberthreats for Patients Act bill text
primary · other · model gpt-5.5

Evidence

FDA says section 3305 added FD&C Act section 524B, effective March 29, 2023, for cybersecurity of medical devices.

Latest lookback check found FDA's current cybersecurity page still points to the general section 524B framework and recent resource updates, not a new China-specific data-location rule.

partial same_term

FDA Cybersecurity
secondary · model gpt-5.5 · confidence 78%

Contest this evidence item

FDA guidance says cyber-device manufacturers must provide SBOMs and architecture information about assets, communication paths, data, code, commands, and servers.

FDA's current guidance implements broad federal review of cyber-device cybersecurity and SBOM information, including server-related architecture, but not a China-only covered-manufacturer regime or explicit patient-data server-location disclosure.

partial same_term

Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
secondary · model gpt-5.5 · confidence 82%

Contest this evidence item

The law requires cyber-device sponsors to submit vulnerability plans, cybersecure processes, updates, patches, and a software bill of materials to FDA.

Congress enacted a general medical-device cybersecurity requirement with SBOM submission to FDA. It partially overlaps the commitment but does not single out Chinese manufacturers or require patient-data server locations.

partial same_term

Public Law 117-328, Consolidated Appropriations Act, 2023
secondary · model gpt-5.5 · confidence 84%

Contest this evidence item

The Senate agreed to the H.R. 2617 motion, 68-29; Cotton (R-AR) is listed as voting Yea.

Cotton voted for the omnibus bill that became Public Law 117-328, which contained section 3305's general cyber-device requirements. This is concrete support for the partial federal action.

partial same_term A for effort

U.S. Senate Roll Call Vote 117th Congress, Vote 421
secondary · model gpt-5.5 · confidence 86%

Contest this evidence item

FDA warned that certain Contec and Epsimed patient monitors could exfiltrate patient data outside the health care environment.

FDA and CISA addressed a specific Chinese-linked patient-monitor cybersecurity problem, including a later software patch, but this was case-specific mitigation rather than the promised disclosure regime for covered Chinese manufacturers.

unresolved same_term

Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication
secondary · model gpt-5.5 · confidence 74%

Contest this evidence item

Assessments

partial same_term A for effort

Congress enacted a broad federal medical-device cybersecurity framework in Public Law 117-328 requiring cyber-device sponsors to submit SBOMs and related cybersecurity information for FDA review, and Cotton voted for the bill. That partially matches the promise. However, the enacted framework is not limited to covered Chinese manufacturers and does not clearly require disclosure of patient-data server locations as promised, so the specific China-focused data-location regime was not delivered.

provider codex_cli · model gpt-5.5 · confidence 84%