S4939119th CongressWALLET

Countering CCP Act

Sponsored By: Senator Cotton, Tom [R-AR]

Introduced

Summary

Creates a targeted cybersecurity review and recall authority for networked medical devices made by manufacturers headquartered in the People’s Republic of China. The bill would have HHS and the FDA, working with the Cybersecurity and Infrastructure Security Agency, demand software bills of materials, data maps, and server location details to spot cybersecurity risks and potential patient data exposure.

Show full summary
  • Patients and families could be notified if a device they use is judged risky and be instructed to stop using it.
  • Health care providers and facilities would get immediate orders and notices to cease use of recalled devices to protect patients and systems.
  • Manufacturers headquartered in the PRC would have 180 days to provide a device’s software bill of materials, data architecture, and server locations or face mandatory recall orders that could be issued within 18 months.
  • HHS, FDA, and CISA must consult on reviews and deliver a report within 2 years analyzing PRC-origin device market share, data protections, and recommendations to strengthen device cybersecurity.

Personalized for You

How does this bill affect your finances?

Personalize government policy and PRIA will tell you what this bill means for your household, plus every other piece of legislation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Bill Overview

Analyzed Economic Effects

2 provisions identified: 1 benefits, 0 costs, 1 mixed.

FDA review and device recalls

This bill would make HHS (through the FDA, with CISA) review certain networked medical devices made by China-linked manufacturers for cybersecurity risks. Within 180 days of enactment, the FDA would ask each maker for a software bill of materials, data mapping and architecture, and locations of systems and servers holding patient data. Within 18 months, the FDA could order any covered device found to pose a cybersecurity risk to stop distribution, tell providers and facilities to stop use, and notify affected patients. The FDA would do the same if a maker fails to provide requested information within 180 days of receiving the request. The FDA could exempt a device from stopping if removing it would cause a dangerous shortage. Within 2 years, the FDA and CISA would report to Congress on industry cyber readiness, PRC market share, data protections, and recommendations.

Which medical devices are covered

This bill would define which devices and makers are subject to the review and recall rules. A "covered device" would be a networked medical device cleared, authorized, approved, or exempted under select FDA pathways on or before March 28, 2023. A "covered manufacturer" would be one headquartered in the People’s Republic of China or owned or controlled by PRC interests, with an exclusion for firms that only have PRC operations or securities. The bill would also define "cybersecurity risk" and what it means for a device to be "networked."

Sponsors & CoSponsors

Sponsor

Cotton, Tom [R-AR]

AR • R

Cosponsors

  • Sen. Banks, Jim [R-IN]

    IN • R

    Sponsored 8/4/2026

Roll Call Votes

No roll call votes available for this bill.

View on Congress.gov
Back to Legislation