Require recalls and immediate distribution stoppages for covered Chinese-made medical devices if the manufacturer fails to provide requested cybersecurity-review information within 180 days.

Tom Cotton · Arkansas · Republican

policy impact 0.70 specificity 0.90 extraction confidence 92%

Contest this claim

Occurrences

for any covered device for which the covered manufacturer fails to submit the information requested under subsection (a)(2)(A) by the date that is 180 days after the date on which such covered manufacturer received such request, the Secretary shall issue for such covered device an order requiring the appropriate person... to immediately cease distribution of such covered device.

The bill would require HHS/FDA to order recalls, distribution stoppages, and notifications for covered devices whose manufacturers do not provide requested review information within 180 days, subject to a patient-shortage exemption.

Countering Chinese Cyberthreats for Patients Act bill text
primary · other · model gpt-5.5

Evidence

Cotton's office says he introduced the Countering Chinese Cyberthreats for Patients Act to have FDA review and recall Chinese-made networked medical devices.

Within the 30-day lookback window, Cotton took concrete legislative action matching the commitment's subject. The source describes introduction of a bill, not enactment or final delivery.

unresolved same_term A for effort

Cotton Introduces Bill to Protect Americans from Chinese-Made Medical Devices
primary · model gpt-5.5 · confidence 94%

Contest this evidence item

The bill text requires HHS/FDA, with CISA, to request cybersecurity-review information from covered Chinese manufacturers and issue orders to immediately cease distribution when a manufacturer misses the 180-day response deadline.

The bill text closely matches the claim, including covered Chinese-made networked medical devices, cybersecurity-review information, a 180-day deadline after the request, and immediate distribution stoppage/notice orders. Because this is proposed bill text, it supports unresolved status with substantial effort, not delivered law.

unresolved same_term A for effort

Countering Chinese Cyberthreats for Patients Act bill text
primary · model gpt-5.5 · confidence 96%

Contest this evidence item

Cotton asked FDA and CISA to review Chinese-made medical devices cleared before March 29, 2023, citing cybersecurity vulnerabilities and patient-data risks.

This pre-lookback but recent official letter shows preparatory executive-branch pressure before the bill introduction. It is serious concrete effort but does not itself create the recall-and-stoppage requirement.

unresolved same_term A for effort

Cotton to FDA: Investigate Dangerous Chinese-Manufactured Medical Devices
primary · model gpt-5.5 · confidence 91%

Contest this evidence item

FDA says current section 524B cybersecurity requirements apply to cyber-device premarket submissions and do not apply to applications submitted before March 29, 2023.

Current FDA guidance confirms the existing federal cybersecurity regime is prospective for premarket submissions and does not establish the retroactive Chinese-made-device recall/stoppage rule described in the claim.

unresolved same_term

Cybersecurity in Medical Devices Frequently Asked Questions (FAQs)
secondary · model gpt-5.5 · confidence 90%

Contest this evidence item

FDA identified Contec/Epsimed patient-monitor vulnerabilities, including remote-control risk, a backdoor, and patient-data exfiltration, and advised some users to unplug and stop using affected devices.

FDA addressed one Chinese-manufactured device problem through safety communications and mitigation advice, later updated for a software patch. This is only narrow partial agency action, not the broader statutory requirement in the claim.

partial same_term

Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication
secondary · model gpt-5.5 · confidence 86%

Contest this evidence item

FDA's recall database lists a Class 2 recall for the CMS8000 Patient Monitor, initiated April 10, 2025, posted May 14, 2025, and still open/classified.

This official recall record supports partial resolution for a specific Contec CMS8000 device, but it does not show enactment of Cotton's proposed 180-day information-request trigger or broad Chinese-made-device stoppage mandate.

partial same_term

Class 2 Device Recall Patient Monitor
secondary · model gpt-5.5 · confidence 84%

Contest this evidence item

Assessments

unresolved same_term A for effort

Cotton introduced the Countering Chinese Cyberthreats for Patients Act in June 2026, and the bill text closely matches the promise by requiring HHS/FDA and CISA review of covered Chinese-made networked medical devices and immediate cease-distribution/notification orders if manufacturers fail to provide requested cybersecurity information within 180 days. However, the record provided and current public evidence show proposed legislation and related pressure on FDA, not enactment of a binding federal recall-and-stoppage requirement. Existing FDA actions and a Contec recall address narrower device-specific risks but do not deliver the broader statutory mechanism promised.

provider codex_cli · model gpt-5.5 · confidence 94%