not later than 18 months after the date of enactment of this Act, the Secretary shall issue for all covered devices that are determined pursuant to the review under subsection (a) to pose a cybersecurity risk an order requiring the appropriate person... to immediately cease distribution of such covered device.
Require recalls and immediate distribution stoppages for covered Chinese-made medical devices found to pose cybersecurity risks.
Occurrences
The Countering Chinese Cyberthreats for Patients (Countering CCP) Act would: Direct the FDA to recall Chinese-made networked medical devices that pose cybersecurity risks to American patients.
Evidence
Cotton's Senate office announced that he had introduced the Countering Chinese Cyberthreats for Patients Act to have FDA review and recall Communist Chinese-made medical devices with cybersecurity risks. The release describes retroactive FDA/CISA review and FDA recalls for risky Chinese-made networked devices.
The bill text would require HHS/FDA, with CISA consultation, to review covered Chinese-manufactured networked medical devices for cybersecurity issues. For devices found risky, FDA would have to order immediate distribution cessation, notices to health professionals and facilities to stop use, and notices to affected individuals.
Cotton sent FDA a letter requesting enhanced review of Chinese-manufactured medical devices for cybersecurity vulnerabilities and asked FDA and CISA to review Chinese-made devices cleared before March 29, 2023.
FDA's recall database lists an open, classified Class II recall for the CMS8000 Patient Monitor by Contec Medical Systems Co., Ltd. in Qinhuangdao, China. The stated recall reason is nine identified cybersecurity vulnerabilities, with customer mitigation actions including network segmentation and disabling the monitor network port.
FDA warned that Contec CMS8000 and relabeled Epsimed MN-120 patient monitors may put patients at risk when connected to the internet, citing remote-control risk, a backdoor, and exfiltration of patient data. FDA advised stopping use where remote monitoring is needed and disconnecting network capabilities for local use.
FDA's cybersecurity page says the 2023 appropriations law added section 524B for medical-device cybersecurity effective March 29, 2023, and lists FDA guidance and safety communications. The page frames these as premarket cybersecurity submissions and general cybersecurity resources rather than a retroactive Chinese-device recall mandate.
Assessments
Cotton materially advanced the promised policy by sending FDA a letter and introducing the Countering Chinese Cyberthreats for Patients Act in June 2026, and the bill text appears to match the requested recall and distribution-stoppage mechanism. But the evidence shows introduction and advocacy only, not enactment or binding implementation. Existing FDA cybersecurity actions and a Contec recall partially overlap with the issue area but do not establish the broad requirement for covered Chinese-made devices that the promise specifies. Because there was a serious legislative attempt without delivery, this is best scored as never with an effort badge.