Since this can be a significant security issue for the state, why doesn't the government sponsor a security audit of the software. Does it upload the data or everything is done on the device? (Also, will have to keep up with the updates)
Because regulation is bad, according to the current executive?
Politics aside, the FDA applies a very generous amount of regulation (mostly justifiable), not sure we want to pay multiples for our consumer electronics, as it (mostly) shows acceptable behavior and rearely kills anybody.
It is bad. Regulations have been historically hijacked to benefit corporate interests. See Intuit and tax policy for example.
Voters on the right naively thought he'd work to fix it. (Wrong!) But it is very much bad for a very large number of issues. Maybe next executive will fix it? (Wrong!)
The NSA has a bad historical reputation for this sort of thing - intentionally weakening crypto standards to make things easier for themselves to break, while keeping them "strong enough" that other agencies outside of NSA/GCHQ/GRU can't. The Crypto AG scandal [0] was pretty bad, with Clipper/Skipjack & Dual_EC_DRBG [1] being more recent ones. The NSA could do what you are asking to do, but they probably won't let us know what the really bad holes are because they want to keep using them.