Not later than 180 days after the date of enactment of this Act, the Secretary, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall request from each covered manufacturer of a covered device such information as is necessary to conduct the review under paragraph (1), including... a software bill of materials... locations of entities, information systems, and servers holding patient data.
Require covered Chinese medical-device manufacturers to provide cybersecurity and data-location information, including software bills of materials and patient-data server locations, for federal review.
Occurrences
Evidence
FDA says section 3305 added FD&C Act section 524B, effective March 29, 2023, for cybersecurity of medical devices.
FDA guidance says cyber-device manufacturers must provide SBOMs and architecture information about assets, communication paths, data, code, commands, and servers.
The law requires cyber-device sponsors to submit vulnerability plans, cybersecure processes, updates, patches, and a software bill of materials to FDA.
The Senate agreed to the H.R. 2617 motion, 68-29; Cotton (R-AR) is listed as voting Yea.
FDA warned that certain Contec and Epsimed patient monitors could exfiltrate patient data outside the health care environment.
Assessments
Congress enacted a broad federal medical-device cybersecurity framework in Public Law 117-328 requiring cyber-device sponsors to submit SBOMs and related cybersecurity information for FDA review, and Cotton voted for the bill. That partially matches the promise. However, the enacted framework is not limited to covered Chinese manufacturers and does not clearly require disclosure of patient-data server locations as promised, so the specific China-focused data-location regime was not delivered.