The "Countering Chinese Cyberthreats for Patients Act" requires the Secretary of Health and Human Services, through the Commissioner of Food and Drugs and in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, to review specific networked medical devices for potential cybersecurity issues. These covered devices are manufactured by entities headquartered in, owned, or controlled by the People's Republic of China. The Secretary will request comprehensive information from these manufacturers, including a software bill of materials , data mapping, and locations of servers holding patient data. This information aims to ensure devices are cybersecure and that patient data is not stored or transferred through systems located in or controlled by the People's Republic of China. If a covered device is determined to pose a cybersecurity risk or if its manufacturer fails to provide the requested information, the Secretary is mandated to issue an order for its recall. This order requires immediate cessation of distribution, notification to health professionals and user facilities to cease use, and notification to affected individuals. An exemption from recall may be granted if it would create a shortage posing a danger to patient health. Additionally, the bill requires a report to Congress within two years, detailing the cyber preparedness of the U.S. device industry, analyzing the market share of Chinese-made devices, and recommending ways to bolster cybersecurity.
Get AI-generated questions to help you understand this bill better
Timeline
Introduced in Senate
Read twice and referred to the Committee on Health, Education, Labor, and Pensions.
Introduced in Senate
Read twice and referred to the Committee on Health, Education, Labor, and Pensions.
Health
Countering CCP Act
USA119th CongressS-4939| Senate
| Updated: 6/24/2026
The "Countering Chinese Cyberthreats for Patients Act" requires the Secretary of Health and Human Services, through the Commissioner of Food and Drugs and in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, to review specific networked medical devices for potential cybersecurity issues. These covered devices are manufactured by entities headquartered in, owned, or controlled by the People's Republic of China. The Secretary will request comprehensive information from these manufacturers, including a software bill of materials , data mapping, and locations of servers holding patient data. This information aims to ensure devices are cybersecure and that patient data is not stored or transferred through systems located in or controlled by the People's Republic of China. If a covered device is determined to pose a cybersecurity risk or if its manufacturer fails to provide the requested information, the Secretary is mandated to issue an order for its recall. This order requires immediate cessation of distribution, notification to health professionals and user facilities to cease use, and notification to affected individuals. An exemption from recall may be granted if it would create a shortage posing a danger to patient health. Additionally, the bill requires a report to Congress within two years, detailing the cyber preparedness of the U.S. device industry, analyzing the market share of Chinese-made devices, and recommending ways to bolster cybersecurity.