Require recalls and immediate distribution stoppages for covered Chinese-made medical devices found to pose cybersecurity risks.

Tom Cotton · Arkansas · Republican

policy impact 0.78 specificity 0.91 extraction confidence 94%

Contest this claim

Occurrences

not later than 18 months after the date of enactment of this Act, the Secretary shall issue for all covered devices that are determined pursuant to the review under subsection (a) to pose a cybersecurity risk an order requiring the appropriate person... to immediately cease distribution of such covered device.

The bill would require HHS/FDA to order recalls, distribution stoppages, notices to health professionals and facilities, and notices to affected individuals for covered devices found to pose cybersecurity risks, subject to a patient-shortage exemption.

Countering Chinese Cyberthreats for Patients Act bill text
primary · other · model gpt-5.5

The Countering Chinese Cyberthreats for Patients (Countering CCP) Act would: Direct the FDA to recall Chinese-made networked medical devices that pose cybersecurity risks to American patients.

Cotton's bill would require FDA recalls of Chinese-made networked medical devices found to pose cybersecurity risks to patients.

Cotton Introduces Bill to Protect Americans from Chinese-Made Medical Devices
primary · press_release · model gpt-5.5

Evidence

Cotton's Senate office announced that he had introduced the Countering Chinese Cyberthreats for Patients Act to have FDA review and recall Communist Chinese-made medical devices with cybersecurity risks. The release describes retroactive FDA/CISA review and FDA recalls for risky Chinese-made networked devices.

Concrete action in the lookback window: Cotton introduced legislation matching the commitment's core mechanism, but the source shows introduction only, not enactment or implementation.

partial same_term A for effort

Cotton Introduces Bill to Protect Americans from Chinese-Made Medical Devices
primary · model gpt-5.5 · confidence 94%

Contest this evidence item

The bill text would require HHS/FDA, with CISA consultation, to review covered Chinese-manufactured networked medical devices for cybersecurity issues. For devices found risky, FDA would have to order immediate distribution cessation, notices to health professionals and facilities to stop use, and notices to affected individuals.

The proposed bill text directly covers recalls and immediate distribution stoppages for covered Chinese-made networked medical devices found to pose cybersecurity risks. It remains a proposal in this evidence, so it supports effort/partial progress rather than delivery.

partial same_term A for effort

Countering Chinese Cyberthreats for Patients Act bill text
primary · model gpt-5.5 · confidence 95%

Contest this evidence item

Cotton sent FDA a letter requesting enhanced review of Chinese-manufactured medical devices for cybersecurity vulnerabilities and asked FDA and CISA to review Chinese-made devices cleared before March 29, 2023.

This earlier official action shows Cotton pressing FDA/CISA to address legacy Chinese-made medical devices before introducing the bill. It is serious effort, but not delivery of a binding recall/stoppage requirement.

partial same_term A for effort

Cotton to FDA: Investigate Dangerous Chinese-Manufactured Medical Devices
primary · model gpt-5.5 · confidence 90%

Contest this evidence item

FDA's recall database lists an open, classified Class II recall for the CMS8000 Patient Monitor by Contec Medical Systems Co., Ltd. in Qinhuangdao, China. The stated recall reason is nine identified cybersecurity vulnerabilities, with customer mitigation actions including network segmentation and disabling the monitor network port.

FDA has taken recall-related action for one Chinese-manufactured patient monitor with cybersecurity vulnerabilities, which partially aligns with the commitment but does not establish the broader statutory requirement Cotton proposed.

partial same_term

Class 2 Device Recall Patient Monitor
secondary · model gpt-5.5 · confidence 88%

Contest this evidence item

FDA warned that Contec CMS8000 and relabeled Epsimed MN-120 patient monitors may put patients at risk when connected to the internet, citing remote-control risk, a backdoor, and exfiltration of patient data. FDA advised stopping use where remote monitoring is needed and disconnecting network capabilities for local use.

This supports the factual basis for the commitment and shows device-specific FDA stop-use/disconnect guidance, but it is not a broad recall-and-distribution-stoppage requirement for covered Chinese-made devices.

partial same_term

Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication
secondary · model gpt-5.5 · confidence 88%

Contest this evidence item

FDA's cybersecurity page says the 2023 appropriations law added section 524B for medical-device cybersecurity effective March 29, 2023, and lists FDA guidance and safety communications. The page frames these as premarket cybersecurity submissions and general cybersecurity resources rather than a retroactive Chinese-device recall mandate.

Current FDA policy activity addresses medical-device cybersecurity generally, but the cited framework does not show delivery of Cotton's specific requirement for recalls and immediate distribution stoppages of covered Chinese-made risky devices.

unresolved same_term

FDA Cybersecurity
secondary · model gpt-5.5 · confidence 82%

Contest this evidence item

Assessments

never same_term A for effort

Cotton materially advanced the promised policy by sending FDA a letter and introducing the Countering Chinese Cyberthreats for Patients Act in June 2026, and the bill text appears to match the requested recall and distribution-stoppage mechanism. But the evidence shows introduction and advocacy only, not enactment or binding implementation. Existing FDA cybersecurity actions and a Contec recall partially overlap with the issue area but do not establish the broad requirement for covered Chinese-made devices that the promise specifies. Because there was a serious legislative attempt without delivery, this is best scored as never with an effort badge.

provider codex_cli · model gpt-5.5 · confidence 91%