The bill strengthens cybersecurity and transparency for networked medical devices—improving patient and system safety and reducing foreign supply-chain risk—but risks near-term device shortages and compliance-driven cost and market impacts that could limit access to needed devices.
Hospitals and patients (including those with chronic conditions) will have higher protection from insecure networked medical devices because HHS/FDA must identify and remove devices that pose cybersecurity risks.
Patients and hospitals will gain more transparency about where patient data are stored and what software components run on devices because manufacturers must provide data locations and a software bill of materials within 180 days.
Taxpayers and health systems will benefit from reduced national cyber risk because the bill requires analysis of higher-risk foreign supply-chain exposure (e.g., PRC-headquartered manufacturers) to inform policies that limit dangerous dependencies.
Patients (especially those with chronic conditions) and hospitals could face delays in care if immediate cessation orders remove devices from use and no substitutes are available.
Device manufacturers (including U.S. subsidiaries) and taxpayers may bear substantial compliance costs and potential market disruption from rapid information requests and possible bans, which could raise device prices or reduce supply.
Hospitals and patients may remain exposed if the bill excludes some manufacturers with PRC operations or publicly traded securities from review, limiting the law's overall protective reach.
Based on analysis of 2 sections of legislative text.
Requires FDA, with CISA consultation, to review and possibly halt distribution of certain networked medical devices tied to PRC-controlled manufacturers, plus reporting to Congress.
Official title: Require the Secretary of Health and Human Services to review certain medical devices manufactured in the People's Republic of China for potential cybersecurity issues, and for other purposes.
Introduced June 24, 2026 by Thomas Bryant Cotton · Last progress June 24, 2026
Requires the Department of Health and Human Services, through the FDA and in consultation with CISA, to review networked medical devices made by manufacturers headquartered in or owned/controlled by the People’s Republic of China for cybersecurity risks. The agency must request detailed product and software information within 180 days, can order cessation of distribution and require notifications for devices that pose cybersecurity risks (with narrow exemptions to avoid patient shortages), and must report to Congress on industry preparedness and policy recommendations within two years. Defines which devices and manufacturers are covered, sets timelines for HHS action (information requests within 180 days, potential distribution stop orders within 18 months), and requires a congressional report analyzing market share, data-security protections, and steps to strengthen medical device cybersecurity related to PRC-origin products.