Texas Gov. Greg Abbott directed state agencies and state-owned medical facilities to audit and inventory patient monitoring devices—particularly Chinese-manufactured equipment—after CISA and the FDA issued federal warnings about cybersecurity risks that could expose sensitive patient data. The directive calls for reviewing equipment used across state-owned facilities and cataloging any medical devices capable of transmitting data, with an emphasis on reassessing cybersecurity policies protecting personal health information (PHI).
Abbott’s letter also instructed agencies and Texas public higher-education systems to ensure new device purchases comply with Texas restrictions on technology from adversarial nations, citing the state’s 2014 policy framework and the more recent executive order GA-48. The communications highlighted specific concern about patient monitors alleged to contain a remote-access backdoor, and reiterated existing prohibitions on certain models, including Contec CMS8000 and Epsimed MN-120, alongside an intent to pursue additional legislation to strengthen protections for Texans’ medical data.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
Abbott's directive set an expected compliance date of April 17 for agencies to complete required review and procurement checks. He also said he would propose legislation in the next session to strengthen protections for Texans' medical data from China and other foreign adversaries.
Governor Greg Abbott directed Texas state agencies, state-owned medical facilities, and higher education institutions to inventory network-capable or remotely accessible medical devices and review cybersecurity policies for protecting health information. The order specifically focused on Contec CMS8000 and Epsimed MN-120 monitors and called for affected devices to be assessed for prohibition under state policy.
Federal warnings from CISA and the FDA identified vulnerabilities and an alleged hidden backdoor in Contec CMS8000 and Epsimed MN-120 patient monitoring devices. The alerts said the flaws could allow remote access, device manipulation, and exfiltration of patient information.
The FDA said Contec had issued patches for vulnerabilities affecting the Contec CMS8000 patient monitor line. These vulnerabilities were tied to concerns about unauthorized access and exposure of sensitive patient data.
The FDA warned that Contec CMS8000 and relabeled Epsimed MN-120 patient monitors contained serious cybersecurity vulnerabilities, including unauthorized remote control, a built-in backdoor, and exfiltration of patient data when connected to the internet. The agency said it was not aware of related injuries or deaths at the time and advised users to disable network connectivity or stop using devices that depend on remote monitoring.
Claroty Team82 analyzed Contec CMS8000 firmware and concluded its communications with Chinese IP addresses were more likely due to insecure design than a deliberately hidden backdoor. The researchers also demonstrated a proof of concept that abused the hardcoded update mechanism to install malicious binaries and gain arbitrary code execution with a reverse shell on the monitor.
Texas Executive Order GA-48 took effect restricting the acquisition or use of certain technology produced by adversarial nations, including China. Later state medical-device review directives explicitly required agencies to ensure procurement compliance with this order.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
8 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcescworld.com
Open sourcehipaajournal.com
Open sourcegov.texas.gov
Open sourcefda.gov
Open sourceclaroty.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.