Protect American Patients from the Threat of Chinese Medical Devices
In 2025, the Food and Drug Administration (FDA) issued a warning about three cybersecurity vulnerabilities found in a connected medical device that threatened patient safety and privacy. According to the notice, three cybersecurity vulnerabilities were found in Contec CMS8000 patient monitors that could “allow unauthorized actors to bypass cybersecurity controls, gaining access to and potentially manipulating the device.” The manufacturer of the device – Contec Medical Systems Co., Ltd. – is based in Qinhuangdao, China.
The backdoor built into these Chinese connected medical devices could have led to adverse care for patients as well as the theft of sensitive health data. As we have warned previously, the legal architecture put in place by the CCP through various laws “together compel any Chinese company to hand its data to the state on demand, in secret, with no independent court able to refuse and no transparency to reveal when it happens.” For precisely these reasons, the American Hospital Association “views the proliferation of Chinese medical devices as a serious threat to the system.”
Senator Tom Cotton Introduces a Bill to Protect American Patients
Following the recall of the Contec CMS8000, Senator Tom Cotton (R-AR) has kept the drumbeat going when it comes to protecting American patients from the Trojan Horse of Chinese-made medical devices. In May, Senator Cotton sent a letter to the FDA asking for an enhanced review of Chinese medical devices that had been cleared prior to March 29, 2023, when statutory requirements became more stringent.
In June, Senator Cotton introduced legislation specifically to combat the cybersecurity threat posed by Chinese medical devices. Called the Countering Chinese Cyberthreats for Patients (Countering CCP) Act, the bill takes a three-part approach to protecting American patients:
First, the bill directs the FDA and the Cybersecurity and Infrastructure Agency (CISA) to conduct a review of Chinese-made connected medical devices approved on or before March 28, 2023, to “provide a reasonable assurance that the covered device and related systems are and will remain cybersecure” and to “provide a reasonable assurance that patient data would not be stored or transferred through systems or servers located in, owned, or controlled by entities headquartered or subject to jurisdiction of the People’s Republic of China.”
Second, the bill directs the FDA to issue a recall for all Chinese-made medical devices that are determined to pose a cybersecurity risk or for which the manufacturer fails tosubmit the requested information.
Third, the bill directs the Department of Health and Human Services (HHS) and CISA to submit a report to Congress that includes “(1) a description of the cyber preparedness and data security of the device industry in the United States; (2) an analysis of the market share of devices used in the United States of manufacturers headquartered in the People's Republic of China; (3) an analysis of data security requirements and protections of devices used in the United States of manufacturers headquartered in or subject to the jurisdiction of the People’s Republic of China; and (4) recommendations for methods to bolster the cyber preparedness of the device industry in the United States.”
If enacted, this bill would be a tangible and welcome step towards securing the safety and privacy of American patients by rooting out insecure devices that pose serious cybersecurity concerns.
China Has a Plan to Dominate the Wearable and Implantable Medical Device Market
The threat to American patients from manipulable medical devices does not just come from legacy connected devices such as patient monitors; indeed, the next frontier of medical devices that could pose a severe cybersecurity threat are brain-computing interfaces (BCIs) that directly link the brain to external devices. In July of 2025, seven departments within the Chinese government jointly authored a new Five-Year Plan that “lays out a road map for China to achieve breakthroughs in BCI technology by 2027 and build an internationally competitive industry by 2030” and establish China as a world leader for such devices. Just this year, Chinese regulators approved “the world’s first minimally invasive BCI device for commercial use.”
As one article explains, however, “the integration of BCIs raises serious cybersecurity and privacy concerns, such as brain tapping, misleading stimuli attacks and adversarial attacks on machine learning components.”
Brain tapping intercepts signals transmitted from the brain to the device and could “be exploited by criminals, terrorists, commercial enterprises, spy agencies and military entities.”
Misleading stimuli attacks manipulate the signal transmitted back to the brain and “introduces a significant risk of hijacking, potentially compelling individuals to engage in actions contrary to their will.”
Adversarial attacks in BCI target “the machine learning component of BCI applications by manipulating training or testing examples, leading to skewed results.”
Clearly, the potential cybersecurity vulnerabilities in brain-computing interfaces have the ability to be much more severe and impactful than even those found in other connected medical devices. Any backdoors introduced in Chinese-made BCIs could be devastating when exploited by malicious actors, meaning we must remain vigilant in order to ensure the safety of American patients.
State and Federal Authorities Can Combat the Threat from Chinese Medical Devices
Senator Cotton’s Countering CCP Act is a welcome piece of legislation that would go a long way towards ensuring that sensitive connected medical devices used in the United States are secure. However, the United States Congress is not the only place that lawmakers can fight against the threats posed by the use of Chinese medical devices. State legislatures can also take steps that will protect the private medical information of American patients from the communist Chinese government.
Below are some of the policy steps that PAI endorses and is working to implement in Washington as well as state capitals across the country.
Banning state Medicaid dollars from flowing to entities that purchase medical devices from Chinese companies.
Directing state purchasing boards to adopt stricter medical device performance standards and restrict any funding for entities that purchase CCP medical devices.
Passing laws at the state level that incentivize the use of domestic alternatives.
Phasing Chinese products out of U.S. hospitals that accept federal funding by 2029.
Requiring that federal healthcare dollars are used on Made-in-America medical devices.
Using trade enforcement laws to ensure Chinese medical equipment is not a threat to national security.
Passing laws to criminalize foreign medical data espionage using medical devices.
Following any national security recommendations that come as a result of ongoing Department of Commerce and Department of Homeland Security investigations.