Not later than 2 years after the date of enactment of this Act, the Secretary, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall submit to... Congress a report that includes... a description of the cyber preparedness and data security of the device industry in the United States... an analysis of the market share... [and] recommendations for methods to bolster the cyber preparedness of the device industry in the United States.
Require HHS and CISA to report to Congress on U.S. medical-device cybersecurity preparedness, Chinese manufacturers' market share and data security practices, and recommendations to improve cyber preparedness.
Occurrences
The Countering Chinese Cyberthreats for Patients (Countering CCP) Act would: Direct HHS and CISA to submit a report to Congress describing cyber preparedness of the U.S. medical device industry, Chinese market share of medical devices made in the U.S., and methods to bolster cyber preparedness of the U.S. medical device industry.
Evidence
FDA’s latest lookback-window entry lists a June 29, 2026 MDIC white paper on medical-device penetration-testing best practices.
FDA’s February 2026 final guidance gives recommendations on device design, labeling, and premarket cybersecurity documentation under FD&C Act section 524B.
Section 3305 added FD&C Act section 524B and required cyber-device submissions to include postmarket vulnerability plans and software bills of materials.
The Senate roll call records Cotton (R-AR) as voting Yea on the H.R. 2617 motion agreed to 68-29.
FDA said Contec/Epsimed monitors included a backdoor and could exfiltrate PII and PHI when connected to the internet.
Assessments
The specific promised outcome, an HHS/CISA report to Congress covering medical-device cybersecurity preparedness, Chinese manufacturers' market share, data-security practices, and recommendations, is not shown as enacted or issued. However, Congress did enact related medical-device cybersecurity requirements in the 2023 Consolidated Appropriations Act, including FDA cybersecurity submission requirements and related FDA/CISA activity, and Cotton voted for that package while serving in the Senate. Later FDA guidance and FDA/CISA safety actions address parts of the cybersecurity-preparedness concern but do not satisfy the China-focused congressional reporting requirement.