WeVote

Bill

Bill

S 4939

Countering CCP Act

119th Congress Introduced by Jim Banks and 1 co-sponsor

The bill requires FDA to assess cybersecurity of Chinese-made networked medical devices and order recalls or halts if risks are found.

Introduced in Senate
0
WeVote Research Nonpartisan
Bill Summary · S 4939

Overview

  • Bill: S. 4939, 119th Congress, 2nd Session
  • Title: Countering Chinese Cyberthreats for Patients Act (Countering CCP Act)
  • Introduced: June 24, 2026 by Senator Tom Cotton; co-sponsored by Jim Banks and Tom Cotton
  • Committee: Health, Education, Labor, and Pensions
  • Purpose: Require the Secretary of Health and Human Services (HHS), through the FDA Commissioner, to review certain medical devices manufactured in the People’s Republic of China (PRC) for potential cybersecurity issues and to pursue recall action if risks are identified.

Main purpose and intent

  • To systematically assess cybersecurity risks of networked medical devices manufactured by Chinese-based or China-controlled companies.
  • To gather information from manufacturers to evaluate cyber threats and data security, and to use that information to determine whether recalls or distribution halts are needed.
  • To enhance U.S. cyber preparedness and data protection in the medical device sector, with reporting to Congress on market and security conditions.

Key provisions and changes

  • Definitions
    • Covered Device: A networked medical device that was cleared/approved under FDA pathways (510(k), 513(f)(2), 515, or 520(m)) on or before March 28, 2023.
    • Covered Manufacturer: A manufacturer headquartered in China or owned/controlled by Chinese entities, or individuals/entities connected to China. Excludes manufacturers with PRC operations solely because they have PRC-related ownership but no other China connection.
    • Cybersecurity Risk: Threats or vulnerabilities involving information systems and data, including consequences from unauthorized access, disruption, or data destruction (including terrorism-related consequences).
    • Networked: Devices with software capable of internet connectivity.
  • Review of devices (Section 2(a))
    • The Secretary of HHS (FDA Commissioner), in consultation with CISA (Cybersecurity and Infrastructure Security Agency), must review each covered device for potential cybersecurity issues.
    • Within 180 days of enactment, the Secretary must request from each covered manufacturer the following information to conduct the review:
    • A software bill of materials (SBOM) for the device, including commercial, open-source, and off-the-shelf components, plus data mapping and architecture documentation.
    • The locations of entities, information systems, and servers holding patient data.
    • Any other information deemed necessary.
    • The Secretary, with CISA, will determine the form and scope of information to request, focusing on processes and procedures that would provide reasonable assurance of cyber security and that patient data would not be stored/transferred through PRC-headquartered or PRC-ruled entities.
  • Recall authority (Section 2(b))
    • If a device is found to pose a cybersecurity risk, the Secretary must issue an order within 18 months after enactment requiring responsible parties (manufacturers, importers, distributors, retailers) to:
    • Cease distribution immediately.
    • Notify health professionals and device user facilities and instruct them to stop using the device.
    • Notify individuals at risk about the device.
    • If a manufacturer fails to provide the requested information within 180 days after receiving the request, an order to halt distribution and recall actions can be issued following the same steps (immediate cessation, notification to professionals/facilities and patients).
    • The Secretary can exempt a device from such an order if implementing the recall would cause a shortage that endangers patient health.
  • Reporting to Congress (Section 2(c))
    • Within 2 years of enactment, the Secretary (with CISA) must provide a comprehensive report to relevant Senate and House committees, including:
    • The cyber preparedness and data security status of the U.S. device industry.
    • Market share analysis of devices used in the U.S. manufactured by PRC-headquartered firms.
    • Analysis of data security requirements for devices from PRC-headquartered or PRC-subject manufacturers.
    • Recommendations to bolster U.S. cyber preparedness in the device industry.
  • Implementation and definitions (Section 2(d))
    • Clarifies the scope of “covered device,” “covered manufacturer,” and “cybersecurity risk.”
    • Emphasizes network connectivity as a criterion for coverage.

Who would be affected

  • Covered manufacturers: PRC-headquartered manufacturers or those owned/controlled by PRC entities; subject to information requests and potential recall actions for their covered devices.
  • Importers, distributors, retailers of covered devices: subject to recall orders and distribution cessation if cybersecurity risks are identified.
  • Health professionals, device user facilities, and patients: recipients of notices and cessation instructions if a device is deemed at risk.
  • U.S. device industry and cybersecurity ecosystem: subject to increased scrutiny, data-sharing requirements, and potential shifts in market share away from PRC-linked devices.

Procedural and timeline considerations

  • 180-day information request window for manufacturers to provide SBOM, data mappings, and data location details.
  • Up to 18 months for the Secretary to issue recall/distribution cessation orders for devices determined to pose cybersecurity risks.
  • Possible exemptions if recalls would cause shortages that threaten patient health.
  • A 2-year post-enactment deadline for the formal legislative report to Congress detailing security status, market shares, and policy recommendations.

Potential impact and considerations

  • Increased scrutiny of Chinese-origin medical devices and tighter control over devices with perceived cybersecurity risks.
  • Potential supply chain implications for hospitals and clinics relying on covered devices, especially if recalls or distribution halts are triggered.
  • Strengthened emphasis on cybersecurity transparency (SBOMs, data mappings) for medical devices.
  • Legislative signal of heightened national security focus on health technology and cross-border data flows.

Compiled from official sources — confirm details with the bill’s official record.

Sign in to ask a question.