Ask the FDA and CISA to review Chinese-made medical devices that were cleared prior to March 29, 2023.

Tom Cotton · Arkansas · Republican

oversight impact 1.00 specificity 0.92 extraction confidence 96%

Contest this claim

Occurrences

I respectfully ask the FDA and CISA to review Chinese-made medical devices cleared prior to March 29, 2023.

Senator Tom Cotton sent a letter to the acting FDA commissioner asking the FDA and CISA to review Chinese-manufactured medical devices that were cleared before March 29, 2023, citing cybersecurity vulnerabilities and risks to patient data and safety.

Cotton to FDA: Investigate Dangerous Chinese-Manufactured Medical Devices
primary · press_release · model gpt-5-mini

The Secretary of Health and Human Services, acting through the Commissioner of Food and Drugs... in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall review each covered device for potential cybersecurity issues.

Cotton's bill would require HHS/FDA, in consultation with CISA, to review covered China-manufactured networked medical devices cleared, authorized, approved, or exempted on or before March 28, 2023 for cybersecurity issues.

Countering Chinese Cyberthreats for Patients Act bill text
primary · other · model gpt-5.5

The Countering Chinese Cyberthreats for Patients (Countering CCP) Act would: Direct the FDA and CISA to conduct a retroactive review of legacy Chinese-made networked medical devices to identify potential cybersecurity risks.

Cotton's bill would require FDA and CISA to conduct a retroactive cybersecurity review of legacy Chinese-made networked medical devices.

Cotton Introduces Bill to Protect Americans from Chinese-Made Medical Devices
primary · press_release · model gpt-5.5

Evidence

FDA updated this safety communication on July 2, 2025 after Contec released a software patch. The page says the agency originally issued the alert on January 30, 2025 about Contec CMS8000 and relabeled Epsimed MN-120 patient monitors, warns that the software included a backdoor, and says FDA and CISA continue working with Contec to correct the vulnerabilities.

Concrete federal review and mitigation activity involving a Chinese-made monitor, but this does not by itself prove Tom Cotton made the specific request to FDA and CISA.

partial same_term A for effort

Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication
secondary · model gpt-5.4-mini · confidence 64%

Contest this evidence item

Assessments

unresolved unknown

The available evidence shows FDA and CISA conducted review and mitigation activity for at least one Chinese-made patient monitor in 2025, which is relevant to the subject of the promise. But it does not show that Tom Cotton himself asked FDA and CISA to conduct the specific pre-March 29, 2023 device review described in the claim, nor that a broader requested review was launched because of his action. Given the gap between the promise language and the proof of candidate action, the claim cannot be credited as delivered on the current record.

provider codex_cli · model gpt-5.4 · confidence 79%