S-4939-119
Read twice and referred to the Committee on Health, Education, Labor, and Pensions.
Sponsored by Tom Cotton (R-AR)
What it does
This bill would require the Secretary of Health and Human Services (HHS), working with the Cybersecurity and Infrastructure Security Agency (CISA), to review all networked medical devices manufactured by Chinese-owned or Chinese-controlled companies that were FDA-cleared on or before March 28, 2023. Manufacturers would have 180 days to submit cybersecurity documentation — including software inventories, data storage locations, and architecture records. Devices found to pose a cybersecurity risk, or whose manufacturers fail to provide the required information, would be subject to mandatory recall orders within 18 months, with a narrow exemption if a recall would create a dangerous shortage. HHS would also submit a report to Congress within two years on the cybersecurity posture of the U.S. medical device industry.
Who benefits
U.S. patients whose health data is collected by networked medical devices, who would gain greater assurance that their data is not accessible to foreign-controlled systems. U.S.-based and allied-nation medical device manufacturers, who would face reduced competition from Chinese-made devices that are recalled or withdrawn. Hospitals and health systems seeking clearer regulatory guidance on device cybersecurity. Domestic cybersecurity firms that may be contracted to assess or replace affected devices. National security and intelligence agencies concerned about foreign access to health infrastructure data.
Who is hurt
Chinese-headquartered or Chinese-controlled medical device manufacturers, who would face mandatory disclosure requirements and potential recall orders. U.S. hospitals, clinics, and device user facilities that rely on affected devices and would need to find replacements, potentially at higher cost or on short timelines. Patients in facilities using recalled devices, who could face care disruptions if substitute devices are unavailable or if the shortage exemption is not applied. Distributors, importers, and retailers of covered devices, who bear direct compliance and recall costs. Healthcare providers in rural or under-resourced settings where device substitution may be more difficult.
Supporters argue
Supporters argue that networked medical devices — including imaging equipment, patient monitors, and infusion pumps — collect sensitive health data and are integrated into critical hospital infrastructure, making them a plausible vector for espionage or disruption. They contend that Chinese law, including the 2017 National Intelligence Law, can compel Chinese companies to cooperate with state intelligence services, meaning devices manufactured or controlled by Chinese entities may pose an inherent data security risk regardless of individual company intent. They further argue that the bill's 18-month review window and shortage exemption provide a measured, evidence-based pathway rather than a blanket ban.
Opponents argue
Opponents argue that the bill's country-of-origin framework may sweep in devices with strong safety records while doing little to address cybersecurity vulnerabilities in non-Chinese devices, which have also been subject to FDA cybersecurity warnings. They contend that mandatory recalls triggered by a manufacturer's failure to respond — rather than a demonstrated vulnerability — could create dangerous device shortages in hospitals that lack ready substitutes, particularly for specialized equipment. They also argue that the bill's definition of "covered manufacturer" based on ownership and control may be difficult to apply consistently given complex global corporate structures, creating legal uncertainty and potential for uneven enforcement.
Constitutional context
Congress has broad authority to regulate medical devices in interstate commerce under the Commerce Clause (Art. I, §8, cl. 3) and to delegate implementation to federal agencies under the Necessary and Proper Clause. Post-Loper Bright (2024), however, courts will independently review HHS and CISA's interpretations of the bill's key terms — such as "cybersecurity risk" and "owned or controlled" — without deferring to agency readings, which could expose implementing regulations to heightened judicial scrutiny.
Checks and balances
The executive branch (HHS/FDA and CISA) gains significant new authority to compel disclosures and issue mandatory recall orders; checks include the bill's statutory timelines, the shortage exemption requiring affirmative agency determination, congressional oversight through the required two-year report, and judicial review of recall orders under the Administrative Procedure Act.
Historical precedent
The federal government has previously restricted Chinese-manufactured telecommunications equipment — most notably Huawei and ZTE products — from federal networks under the 2019 National Defense Authorization Act and FCC rules, establishing a precedent for country-of-origin-based exclusions on national security grounds.