Senator · R-AR
The bill strengthens medical‑device cybersecurity and transparency—reducing national cyber risk and protecting patients—but risks short‑term device shortages and compliance costs and may leave gaps where certain foreign‑linked manufacturers are excluded.
Hospitals and patients (especially those with chronic conditions) will have fewer insecure networked medical devices in clinical use because HHS/FDA must identify and remove devices that pose cybersecurity risks.
Taxpayers and healthcare providers benefit from reduced national cyber risk because the bill directs analysis of higher‑risk PRC‑headquartered manufacturers' market share and data‑security protections to inform policy responses.
Patients and hospitals gain greater transparency about where patient data are stored and what software components run on devices because manufacturers must provide data locations and a software bill of materials within 180 days.
Patients and hospitals may experience care delays or interrupted services if immediate cessation orders remove devices and suitable substitutes are not available, creating short‑term shortages.
Manufacturers (including U.S. subsidiaries) could face significant compliance costs and market disruption from rapid information demands and possible bans, which may raise device prices or reduce supply for purchasers and taxpayers.
Exclusions for some manufacturers with PRC operations or publicly traded securities could leave vulnerable devices unreviewed, limiting protections for hospitals and patients despite the law's intent.
Based on analysis of 2 sections of legislative text.
Directs HHS/FDA (with CISA input) to review networked medical devices from PRC‑controlled manufacturers for cybersecurity, require information, halt distribution if risky, and report to Congress.
Requires HHS, through the FDA and in consultation with CISA, to review networked medical devices made by manufacturers headquartered in or controlled by the People’s Republic of China for cybersecurity risks. The FDA must request detailed information (including a software bill of materials and data location), may order cessation of distribution and require notification when a device poses a cybersecurity risk or when a covered manufacturer fails to provide required information, and may exempt a device from removal if a recall would cause a harmful shortage. Also requires a congressional report within two years analyzing industry cyber preparedness, market share of PRC-headquartered manufacturers, protections for data tied to PRC-origin devices, and recommendations to strengthen medical device cyber defenses. Timelines: information requests within 180 days, enforcement authority within 18 months, and reporting within two years of enactment.
Official title: Require the Secretary of Health and Human Services to review certain medical devices manufactured in the People's Republic of China for potential cybersecurity issues, and for other purposes.
Introduced June 24, 2026 by Thomas Bryant Cotton · Last progress June 24, 2026