Summary#
This bill requires the Health and Human Services Secretary, through the FDA and working with the Cybersecurity and Infrastructure Security Agency (CISA), to review certain internet‑connected medical devices made by manufacturers tied to the People’s Republic of China (PRC) for cybersecurity risks. The bill gives the Secretary authority to order stops to distribution and use of devices found to pose a cybersecurity risk or of devices whose manufacturers fail to provide requested information. It also requires a report on device industry preparedness and the role of PRC‑linked manufacturers.
- Main change: FDA must review covered networked medical devices made by PRC‑headquartered or PRC‑controlled manufacturers and can order recalls or stops to distribution and use if devices pose cybersecurity risks or if required information is not provided.
- Information required: Manufacturers must provide a software bill of materials (SBOM), data‑mapping and architecture documentation, and locations of systems or servers holding patient data.
- Deadlines: FDA must request information within 180 days of enactment, may issue recall orders within 18 months for risky devices (or for nonresponse), and must deliver a report to Congress within 2 years.
- Exemption: The Secretary may exempt a device from a stop/use order if removing it would cause a dangerous shortage for patients.
- Scope: Covered devices are networked devices cleared or authorized on or before March 28, 2023 and made by manufacturers headquartered in the PRC or owned/controlled by PRC entities.
What it means for you#
- Patients: Some devices could be taken out of use if they are found to be a cybersecurity risk or if manufacturers do not provide required information. The Secretary can exempt devices if stopping them would create a dangerous shortage.
- Health professionals and hospitals (device user facilities): If the Secretary issues a stop‑use order, facilities must cease using the affected device and must be notified. Facilities may need to find replacements or change clinical workflows if replacement devices are not available.
- Manufacturers headquartered in the PRC or owned/controlled by PRC entities: Must submit technical documentation (including SBOMs and data‑location details) within the requested time. If they fail to provide information, FDA may order immediate cessation of distribution and use of their covered devices.
- Importers, distributors, and retailers: Could be told to immediately stop distributing covered devices that FDA finds risky or for which manufacturers do not comply.
- Federal agencies (FDA and CISA): Will carry out technical reviews and coordinate on assessments, and must prepare a congressional report on industry preparedness and market share of PRC‑linked manufacturers.
Expenses#
No publicly available information.
- The bill requires FDA and CISA to perform technical reviews and to prepare a report, which would likely increase administrative and staff costs for those agencies.
- Covered manufacturers would likely incur costs to assemble and submit SBOMs, data‑mapping, and architecture documentation.
- Health care facilities and distributors could face costs to replace or remove devices if FDA issues stop‑use orders, and possible costs to manage care where device replacements are not immediately available.
- The bill does not provide a funding source or estimate for these activities in the text provided.
Proponents' View#
- The bill appears intended to reduce cybersecurity risks from networked medical devices that are made by manufacturers tied to the PRC.
- A possible argument for the bill is that requiring SBOMs and data‑location details increases transparency and helps regulators spot vulnerabilities and data flows that could risk patient privacy or device integrity.
- The recall/stop authority is intended to let FDA quickly remove or limit use of devices judged to present cybersecurity threats.
- The required report could identify market exposure and recommend steps to strengthen the device sector’s cyber preparedness.
Opponents' View#
- One concern is that requiring immediate cessation of distribution and use could create sudden device shortages and disrupt patient care, even though the bill allows an exemption if a shortage would be dangerous.
- The bill does not clearly explain how “owned or controlled” will be judged, which may make it hard for some manufacturers to know whether they are covered.
- The standard for what counts as a cybersecurity risk and what provides a “reasonable assurance” is not defined in technical detail, leaving room for uncertainty in enforcement.
- It is unclear how patient data privacy and commercial confidentiality of submitted technical information (like SBOMs or network maps) will be protected.
- The bill does not include a fiscal estimate or funding for the expanded review and potential recall activity, so the administrative and replacement costs are not identified.