Skip to content
Senator Demands Review of Chinese Medical Device Security

Senator Demands Review of Chinese Medical Device Security

Mddionline May 27, 2026

Senator Tom Cotton urges FDA to review pre-2023 Chinese-made medical devices after cybersecurity vulnerabilities in recalled patient monitors exposed thousands to data theft and remote device hijacking.

On May 26, Tom Cotton, a U.S. Senator from Arkansas, published a letter to acting FDA Commissioner Kyle Diamantas regarding cybersecurity vulnerabilities associated with networked medical devices manufactured in China.

“American patients' exposure to compromised Chinese-made medical devices poses a risk to both national security and public health,” Cotton wrote in the letter.

At the beginning of 2025, FDA and the Cybersecurity and Infrastructure Security Agency warned patients cybersecurity vulnerabilities associated with the Contee CMS8000, a networked patient monitoring device manufactured in China.

During the investigation, FDA determined that the device would take personally identifiable patient health information from users when connected to the internet.

Cotton warned that this kind of data extraction may lead to identity theft, insurance fraud, extortion, and more sophisticated scams against American patients.

CISA noted that Contee CMS8000 was programmed to allow unverified users to remotely control the device without a health provider's knowledge.

On May 14, 2025, FDA issued a Class II recall of the Contee CMS8000 . According to FDA records, seven thousand monitors were recalled, yet they remain on the market today.

Beginning in 2023, FDA started requiring medical device manufacturers to demonstrate enhanced cybersecurity safeguards to receive FDA pre-market clearance.

This requirement did not impact medical devices that received clearance prior to 2023.

“I respectfully ask the FDA and CISA to review Chinese-made medical devices cleared prior to March 29, 2023. Protecting Americans' privacy and ensuring their health data isn't accessible to cybercriminals in adversarial nations is of utmost importance,” Cotton wrote in his request.

This letter comes two months after Greg Abbott, the governor of Texas, ordered agencies in the state to investigate connected medical devices made in foreign countries with a specific focus on those manufactured in China.

The investigation focuses on devices used in state-owned facilities, which Abbott believes could pose cybersecurity risks for patients and workers.

Abbott launched the investigation on March 9 as part of a larger initiative from Republicans in the state to “protect Texans from hostile foreign adversaries like the Chinese Communist Party.”

The investigation focused on Contec CMS8000 devices, as well as Epsimed MN-120 patient monitors, which were also recalled at the end of 2025 due to a “hidden backdoor” that threatened cybersecurity.

Texas’ investigation and Abbott’s request come on the heels of several major cyberattacks that have taken the medtech industry by storm in 2026.

Recent cybersecurity incidents have targeted Stryker , Intuitive Surgical , UFP Technologies , and Medtronic .

As of early 2026, 22% of healthcare organizations have experienced at least one cyberattack targeting medical devices, while ransomware attacks on the healthcare sector surged by 30% in 2025, with 293 attacks recorded against hospitals and direct care providers.

“The digitization of healthcare has revolutionized the delivery of patient care. Connected medical devices—from insulin pumps and cardiac implants to networked infusion pumps and diagnostic imaging systems—enable real-time monitoring, remote adjustments, and seamless data integration into electronic health records. However, this connectivity comes at a high cost: each connected device represents a potential entry point for cyberattacks,” Partha Anbil, SVP, Life Sciences at Coforge Limited, writes.

“The challenge is particularly acute with Class III medical devices, which sustain or support life and pose the greatest risk to patients if compromised. FDA estimates that 164 out of every 1,000 devices remain vulnerable to cyberattacks.”

This is not the first time leaders of the Republican party have taken steps to investigate China-made medical devices.

In September, the Trump Administration initiated a Section 232 investigation into medical equipment and devices .

Section 232, part of the Trade Expansion Act of 1962, allows the Secretary of Commerce to determine the effects on the national security of imports of personal protective equipment, medical consumables, and medical equipment including devices. The implementation of 232 impacted China, a key trading partner to the U.S. and a top manufacturer of medical devices.

Since the start of Donald Trump’s presidency, the U.S. has imposed tariffs against China, usually sitting somewhere around 100% .

As a result, major companies have started moving operations out of the country over the last year.

“We've seen a big shift out of the Chinese manufacturing market because in addition to the IEEPA tariffs, they were also subject to the Section 301 tariffs that were implemented back in 2018 and 2019 under the first administration. And so moving manufacturing or having a partnered firm or manufacturer/supplier outside of China is probably a better long term strategy that does come with the cost of capital investment and shopping around and so forth,” John Burhans, chief trade officer at Mercury and a licensed U.S. Customs Broker, told MD+DI .

Lisa Voronkova, CEO of OVA Solutions, recently warned that Chinese manufacturers now supply half of U.S. hospitals' basic medical consumables and a growing of critical equipment, creating dangerous dependencies.

In March 2025, the Senate Intelligence Committee held hearings that exposed longstanding industry concerns Chinese manufacturers. These hearings revealed a pattern in which Chinese entities intentionally installed vulnerabilities in devices.

Although not every product is compromised, the frequency and nature of these vulnerabilities have raised significant security alarms. This situation has escalated to the point that the American Hospital Association now identifies it as 'a serious threat to the system,' warning that attacks disrupting care constitute 'a threat-to-life crime.'

Senator Tom Cotton's call for FDA to review pre-2023 Chinese-made medical devices underscores growing bipartisan concern over cybersecurity vulnerabilities in connected healthcare technology.

With devices like the Contec CMS8000 exposing patient data and allowing unauthorized remote access, lawmakers are demanding action to protect Americans from potential espionage and cyberattacks.

This push follows Texas Governor Greg Abbott's state-level investigation and comes amid a surge in healthcare cyberattacks—293 ransomware incidents in 2025 alone.

As the Trump Administration's tariffs and Section 232 investigation pressure manufacturers to relocate operations outside China, the medical device industry faces a critical inflection point: balancing supply chain dependencies with national security imperatives.

With Chinese manufacturers supplying half of U.S. hospitals' basic consumables and FDA estimating 164 out of every 1,000 devices remain vulnerable to cyberattacks, the stakes for patient safety and data security have never been higher.

Senior Writer, Informa Markets – Engineering

Claire Wallace is a senior staff writer at Medical Device + Diagnostics Industry (MD+DI) , where she covers key developments in the healthcare and medical device industry. With nearly a decade of journalism experience, she brings a deep understanding of the healthcare industry and a proven ability to connect with physicians, medtech leaders, and policy experts on the issues shaping care delivery today. She is committed to delivering nuanced coverage that helps industry professionals anticipate trends, understand regulatory shifts, and identify opportunities in an increasingly complex healthcare ecosystem.

Before joining MD+DI , Claire spent three years at Becker’s Healthcare as a writer and assistant editor, leading coverage on developments across orthopedics, outpatient care, cardiology, and gastroenterology that bridged perspectives from clinicians and healthcare executives. Her reporting background also includes lifestyle, political, and clean energy news, with bylines in various national and digital publications. Claire earned her bachelor’s degree in Communications and Media & Screen Studies from Northeastern University, where she also minored in Political Science and Journalism. She holds a master’s degree in Media Advocacy and is currently based in Chicago.

Extracted Entities