I respectfully ask the FDA and CISA to review Chinese-made medical devices cleared prior to March 29, 2023.
Ask the FDA and CISA to review Chinese-made medical devices that were cleared prior to March 29, 2023.
Occurrences
I respectfully ask the FDA and CISA to review Chinese-made medical devices cleared prior to March 29, 2023.
The Secretary of Health and Human Services, acting through the Commissioner of Food and Drugs... in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall review each covered device for potential cybersecurity issues.
The Countering Chinese Cyberthreats for Patients (Countering CCP) Act would: Direct the FDA and CISA to conduct a retroactive review of legacy Chinese-made networked medical devices to identify potential cybersecurity risks.
Evidence
FDA updated this safety communication on July 2, 2025 after Contec released a software patch. The page says the agency originally issued the alert on January 30, 2025 about Contec CMS8000 and relabeled Epsimed MN-120 patient monitors, warns that the software included a backdoor, and says FDA and CISA continue working with Contec to correct the vulnerabilities.
Assessments
The available evidence shows FDA and CISA conducted review and mitigation activity for at least one Chinese-made patient monitor in 2025, which is relevant to the subject of the promise. But it does not show that Tom Cotton himself asked FDA and CISA to conduct the specific pre-March 29, 2023 device review described in the claim, nor that a broader requested review was launched because of his action. Given the gap between the promise language and the proof of candidate action, the claim cannot be credited as delivered on the current record.