Require HHS and CISA to report to Congress on U.S. medical-device cybersecurity preparedness, Chinese manufacturers' market share and data security practices, and recommendations to improve cyber preparedness.

Tom Cotton · Arkansas · Republican

oversight impact 0.50 specificity 0.88 extraction confidence 95%

Contest this claim

Occurrences

Not later than 2 years after the date of enactment of this Act, the Secretary, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall submit to... Congress a report that includes... a description of the cyber preparedness and data security of the device industry in the United States... an analysis of the market share... [and] recommendations for methods to bolster the cyber preparedness of the device industry in the United States.

The bill would require HHS/FDA and CISA to submit a report to Congress within two years on device-industry cybersecurity, Chinese manufacturers' U.S. market share and data security, and recommendations for strengthening preparedness.

Countering Chinese Cyberthreats for Patients Act bill text
primary · other · model gpt-5.5

The Countering Chinese Cyberthreats for Patients (Countering CCP) Act would: Direct HHS and CISA to submit a report to Congress describing cyber preparedness of the U.S. medical device industry, Chinese market share of medical devices made in the U.S., and methods to bolster cyber preparedness of the U.S. medical device industry.

Cotton's bill would require HHS and CISA to report to Congress on medical-device cybersecurity preparedness, Chinese market share, and ways to strengthen preparedness.

Cotton Introduces Bill to Protect Americans from Chinese-Made Medical Devices
primary · press_release · model gpt-5.5

Evidence

FDA’s latest lookback-window entry lists a June 29, 2026 MDIC white paper on medical-device penetration-testing best practices.

Within the June 11-July 10, 2026 lookback window, FDA shows continued cybersecurity-resource activity, but not an HHS/CISA report to Congress on Chinese manufacturers, market share, or data-security practices.

unresolved same_term

FDA Cybersecurity
secondary · model gpt-5.5 · confidence 78%

Contest this evidence item

FDA’s February 2026 final guidance gives recommendations on device design, labeling, and premarket cybersecurity documentation under FD&C Act section 524B.

This is a concrete medical-device cybersecurity action by HHS/FDA, but it is guidance for industry rather than the promised congressional report on preparedness and Chinese manufacturers.

partial same_term

Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
secondary · model gpt-5.5 · confidence 82%

Contest this evidence item

Section 3305 added FD&C Act section 524B and required cyber-device submissions to include postmarket vulnerability plans and software bills of materials.

Congress enacted broad medical-device cybersecurity requirements and directed FDA, in consultation with CISA, to update guidance/resources and required a GAO report on device cybersecurity challenges. It did not appear to require the specific HHS/CISA congressional report on Chinese manufacturers’ market share and data practices.

partial same_term

H.R. 2617, Consolidated Appropriations Act, 2023, Enrolled Bill
secondary · model gpt-5.5 · confidence 86%

Contest this evidence item

The Senate roll call records Cotton (R-AR) as voting Yea on the H.R. 2617 motion agreed to 68-29.

Cotton took a concrete vote for the package that enacted section 3305’s medical-device cybersecurity provisions, but that vote did not fully deliver the Chinese-manufacturer reporting commitment.

partial same_term A for effort

U.S. Senate Roll Call Vote 117th Congress, Vote 421
secondary · model gpt-5.5 · confidence 84%

Contest this evidence item

FDA said Contec/Epsimed monitors included a backdoor and could exfiltrate PII and PHI when connected to the internet.

FDA and CISA acted on a concrete medical-device data-security threat and issued mitigation recommendations, but this was a safety communication, not the promised HHS/CISA report to Congress on market share and preparedness.

partial same_term

Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication
secondary · model gpt-5.5 · confidence 80%

Contest this evidence item

Assessments

partial same_term A for effort

The specific promised outcome, an HHS/CISA report to Congress covering medical-device cybersecurity preparedness, Chinese manufacturers' market share, data-security practices, and recommendations, is not shown as enacted or issued. However, Congress did enact related medical-device cybersecurity requirements in the 2023 Consolidated Appropriations Act, including FDA cybersecurity submission requirements and related FDA/CISA activity, and Cotton voted for that package while serving in the Senate. Later FDA guidance and FDA/CISA safety actions address parts of the cybersecurity-preparedness concern but do not satisfy the China-focused congressional reporting requirement.

provider codex_cli · model gpt-5.5 · confidence 82%