Texas Governor Warns of Cyber Risks in Chinese Medical Devices

Texas Governor Warns of Cyber Risks in Chinese Medical Devices

.

Texas Gov. Greg Abbott on March 9 directed state agencies and medical facilities to address potential cybersecurity risks associated with using medical equipment made in China.

In a March 9 letter to Texas agencies, Abbott raised concerns that Texans’ medical data could be at risk, pointing to federal warnings over specific medical device cybersecurity vulnerabilities.

“These risks include the ability of unauthorized actors to access protected health information remotely,” Abbott wrote.

According to the U.S. Food and Drug Administration, nearly half of medical devices are imported. Census data showed that in 2024, $102 billion worth of medical equipment was imported, with nearly $15 billion of that from China. Medical equipment has been an area where imports from China have had tariff exemptions extended several times.

Abbott referred to an executive order he issued in November 2024 ordering Texas agencies to harden networks against Chinese cyberthreats, and directed the agencies to review all state-owned medical facilities and public systems of higher education to make sure medical devices and future procurement don’t carry this risk.

He also directed the agencies to implement cyberpolicies to protect patient health data, and the Texas Health and Human Services Commission to create an awareness campaign about recruiting concerns related to cybersecurity. Abbott also ordered relevant agencies to submit recommendations for updating policies to mitigate cybersecurity risks by April 17.

The Chinese communist regime is considered one of the world’s top cyberthreats, with cyber and defense agencies in countries around the globe increasingly warning in recent years of Chinese hacking of allied networks.

Cyberespionage is a top concern, and agencies from 23 cyber, defense, and intelligence agencies from the United States and other countries released a joint advisory last August, breaking down just one Chinese state-sponsored cybercampaign that had breached major telecommunication, hospitality, and transportation networks to track targets around the world.

Officials have also warned that Chinese state-sponsored hacking has breached critical infrastructure systems in what they believe could be used for disruption in the event of a conflict.
President Donald Trump recently released the national Cyber Strategy, which acknowledged the “tremendous costs” imposed by malicious cyberactors and outlined six “pillars” to disable these threats.

In addition to disrupting adversary cybercampaigns, the United States “will not confine our responses to the ‘cyber’ realm” but will also use foreign policy, trade, and other means to impose costs on hackers, according to the document.

“Our adversaries have and will increasingly feel the consequences of their actions; we will dismantle networks, pursue hackers and spies, and sanction lawless foreign hacking companies,” the strategy reads. “We will unveil and embarrass online espionage, destructive propaganda and influence operations, and cultural subversion.”

.