Spring til indhold
Hub Nexus
Opdateret

ForfatterIngen forfatter endnuOvertag den

Ser du noget at forbedre? Foreslå en ændring.

Støtte

Denne side er offentlig.

I Professionalism · side 93 af 344

The Therac-25 was a poorly programmed radiation therapy machine which overdosed several patients in the mid-1980s.[1]

Background

Atomic Energy of Canada Limited (AECL), a crown corporation of the Canadian government, began developing the Therac-25 in the late 1970s and took it fully computerized to the healthcare market in 1982.[1][2] Like earlier medical linear accelerators, the Therac-25 was designed to deliver high-energy electron beams to destroy tumors without damaging nearby healthy tissue.[1]

A defining feature of the Therac-25 was that it combined two fundamentally different treatment modes in a single machine. In electron-beam mode, the device delivered relatively low-energy radiation for surface-level tumors. In X-ray (photon) mode, it delivered much higher-energy radiation intended to penetrate deep tissue. Although these modes differed greatly in risk and intensity, they were operated through the same user interface and controlled by the same software system.

Unlike its predecessor, the Therac-6 and Therac-20, the Therac-25 heavily relied on software rather than mechanical safety interlocks to control beam configuration and prevent dangerous operating states.[1] Earlier machines used physical hardware safeguards that made certain errors impossible. In the Therac-25, many of these protections were removed and replaced with software logic, a design decision that reduced cost and complexity but also shifted responsibility for safety almost entirely onto the correctness of the software.

This reliance on software control had important ethical implications. In a safety-critical medical system, software errors do not merely cause inconvenience or financial loss; they can directly harm patients. By treating software as a flexible control mechanism rather than as a safety-critical component requiring independent verification and rigorous testing, AECL created conditions in which small programming errors could lead to catastrophic outcomes.

The Therac-25 thus represents an early and influential example of the ethical risks introduced when complex software systems are entrusted with life-critical functions without corresponding changes in engineering practice, testing standards, and professional responsibility.

Incidents

Between 1985 and 1987 there were six recorded accidents involving the Therac-25 resulting in massive radiation overdose to patients. All of these incidents resulted in either death or serious injury.[2] Although each incident initially appeared isolated, its similarities revealed a recurring failure pattern rather than independent malfunctions.

The first incident occurred on June 3, 1985 at the Kennestone Regional Oncology Center in Marietta, Georgia. The patient was prescribed a 10-MeV electron treatment to her clavicle area, but when the machine turned on she felt a "tremendous force of heat... [a] red-hot sensation." There was no visible sign of tissue damage immediately following treatment, but after going home, the area began to swell and became extremely painful. The patient developed burns all the way through to her back; eventually she needed to have a breast removed and lost the use of her shoulder and arm. Following this incident, the hospital physicist inquired with AECL if an electron beam could be administered without the beam spreader plate in place. AECL incorrectly responded that it was not possible.[2]

The second incident occurred in Hamilton, Ontario, Canada on July 26, 1985. The patient was receiving radiation treatment to a region near the hip. Six times the operator tried to administer treatment, but the machine shut down with an "H-tilt" error message. The operator did not know what this meant but reported it to the hospital technician. The machine's display read "no dose" after each treatment attempt, but when the patient died from cancer a few months later, an autopsy revealed that the patient had such intense radiation burns that he would have required a hip replacement. The incident was reported to AECL.[2]

The third incident occurred in Yakima, Washington, in December 1985. Similar to the first case, the patient received a radiation overdose but no cause could be found. The technicians at the hospital contacted AECL about the incident but AECL responded saying that an overdose was not possible and no other incidents had been reported.[2]

The fourth and fifth incidents occurred at the East Texas Cancer Center in March and April 1986. These two incidents were similar because both patients were prescribed electron beam radiation, but during the setup for both treatments, the operator accidentally pressed X for X-ray, then quickly changed it to E for electron beam before turning on the beam. Both times, the display read MALFUNCTION 54 and displayed a gross under dose. The operator's manual made no mention of MALFUNCTION 54 error code. In the first instance, the operator quickly restarted the treatment, but received the same error message. At this time the patient was pounding furiously at the door of the treatment room and was complaining about receiving an electric shock. The hospital shut down the machine for a day, during which engineers and technicians from the hospital and from AECL tested the machine but were unable to replicate the error. After the second incident that resulted in another apparent overdose, the hospital physician ran his own tests and was finally able to replicate the error, determining that it was caused by the speed at which the change from X-ray mode to electron mode occurred. Unfortunately, both patients involved in these incidents died from their radiation exposure.[2]

The sixth and final incident involving the Therac-25 occurred in January 1987, again in Yakima, Washington. Similar to the first three incidents, the operator tried to administer a treatment but an ambiguous error message was displayed. Believing that little or no radiation had been delivered, the operator tried again. Again, the patient complained of a burning sensation and visible reddening of the skin occurred as in the last incident in Yakima. It was determined that the patient had received an overdose, but it was still unclear how it had occurred. AECL began investigating the incident and identified additional software errors. Unfortunately, this patient died from complications related to the overdose in April that year.[2]

By the third incident, the claim that these events were isolated or inexplicable was no longer credible. By the sixth, the repetition of similar operator actions, misleading error messages, and severe overdoses demonstrated a systemic failure rather than accidental misuse or hardware malfunction.

Engineering failures and responses

The Therac-25 had several engineering failures that could have been averted through the use of independent verification, formal software specification, or more significant testing. AECL's initial responses to the flaws were deficient, and significant changes were not made until they were forced by the FDA to issue a corrective action plan in July 1987, two years after the first incident.[1]

Lack of documentation

The Therac-25's error codes, such as the infamous MALFUNCTION 54, were not mentioned in the operator's manual and were only acknowledged in the maintenance manual. Operators were also not informed whether any of the errors affected patient safety. Error messages that occurred most frequently were insignificant, so errors that were actually serious were sometimes ignored.[1]

The operator in the Tyler, TX hospital had a sheet of error codes taped to the machine. It indicated that MALFUNCTION 54 meant "dose input 2 error" (p. 17), which was also not explained anywhere. It was intended for AECL internal testing use only, and eventually one AECL technician explained that it meant "a dose had been delivered that was either too high or too low" (p. 17).[1]

When the AECL responded to the other software errors, they stated that documentation was a low priority. They did not further address this issue until they agreed to replace the MALFUNCTION codes with more descriptive error messages as part of the corrective action plan.[1] Documentation is a critical part of any complex software system, especially one in which errors can have an impact on human life.

Race Condition (Tyler Error)

Code reuse from the Therac-20 was responsible for the accidents that occurred in Tyler, TX. The error occurred when the operator attempted to switch from the X-ray beam to the electron beam and then very quickly began the treatment. If the operator was fast enough, the beam would be activated after the beam flattener was moved but before the X-ray beam was shut down and the electron beam was turned on.

Later investigation showed that Tyler overdoses were linked to a software race condition: the Therac-25 processed rapid operator edits in a keyboard-handling task while a separate control task was determining whether treatment entry was complete and preparing the machine for its usage. In a small window of time, the operator could change the mode and see the change reflected on the screen, but the control logic could proceed with an inconsistent (outdated) internal state because the two tasks shared variables and did not have adequate, safe synchronization.

A safer design would verify a consistent state and treat changes as atomic. It also would have blocked the usage of the beam while the changes were in progress and required that the machine confirm its change when it was finished. Race conditions are common in software and hardware projects and are issues that must be thoroughly protected against to avoid such failures.

The Therac-20 and Therac-25 had the same software for controlling the switch between the electron and X-ray beams. However, if this same sequence occurred on the Therac-20, the machine would simply blow a fuse and shut down because it had hardware interlocks that prevented the X-ray from firing without the beam flattener. The Therac-25 had only software interlocks, which were faulty.[1]

Initially, AECL's solution to the problem was to physically disable the "up" key on all Therac-25 operators' keyboards. Then, if the operator were to input the incorrect beam type, or err on any data entry, he would be forced to restart the process. Hardware and software updates for all Therac-25s came much later as another part of the corrective action plan. Hardware interlocks were added similar to the Therac-20's to prevent the X-ray beam from firing without the beam flattener, and the software bug was fixed.[1]

It is poor engineering practice to copy a solution from one project to another without considering the differences between them. The Ariane 5, an unmanned rocket, is another case in which code reuse lead to failure. The first test rocket exploded mid-flight because its software was from the Ariane 4. The Ariane 5 had a very different initial trajectory than the Ariane 4 and this difference caused a software exception which eventually stopped the computations, prevented correct navigation, and triggered a self-destruct mechanism.[3]

Yakima Software Bug

Odometer rollover, a common real-world example of integer overflow .

Odometer rollover, a common real-world example of integer overflow . (Image: Hellbus, Public domain)

The bug that caused the second overdose at the Yakima Valley Memorial Hospital was a result of integer overflow. During the setup phase of the treatment, the program used a counter to indicate whether the inputted parameters matched the prescribed treatment. If the parameters matched, the value of the counter was set to zero, and the treatment could proceed. Otherwise, the counter was incremented. The problem was that the counter was stored as an 8-bit integer, so it could hold a maximum value of 255. If the counter incremented again, it would wrap around back to zero. If the operator attempted to start the treatment at the precise time when the counter wrapped around to zero, then they could start treatment with the incorrect prescription.[1]

The solution was to pick an arbitrary nonzero number to assign to the counter when the parameters were incorrect, so that it could never be zero unless the prescription was entered properly.[1] While this sort of timing would be difficult to catch during testing, formal software specifications could have described the precise conditions under which the counter would have a value of zero. Another programmer performing an independent analysis of the code would also likely have been able to catch this error.

Professional Concerns

This case of professional negligence raises a variety of concerns about safe practices, especially in medical systems. Two important topics are the responses after the occurrences of the Therac-25 incidents of both the hospital staff and the AECL.

Due Diligence from AECL

Much like its insufficient testing prior to taking the Therac 25 to market, AECL's responses to user complaints were inadequate. AECL's hubris and continued dismissiveness led to repeated failures to fulfill professional obligations. The first contact from Kennestone Regional Oncology Center should have prompted an immediate suspension of clinical use, a full engineering analysis, and notification of all other hospitals operating the device. Instead, AECL reassured users that an overdose was impossible. This was a serious professional failure, particularly given the severity of the patient's injuries.

After the second incident in Hamilton, AECL had a second opportunity to reevaluate its assumptions about system safety. By this point, two independent hospitals had reported unexpected patient harm during normal operation. AECL should have initiated broader communication with all users, conducted on site investigations, and escalated concerns to regulatory bodies. Instead, the company treated the case as an isolated anomaly and maintained that the system was functioning properly. This response reflected a failure to recognize the implications of recurring harm and a disregard for the ethical obligation to act in the face of uncertainty.

By the third incident in Yakima, the “fluke” explanation was no longer tenable. AECL now had consistent reports from multiple institutions involving similar symptoms, ambiguous error messages, and unexplained overdoses. At this stage, the company should have undertaken a comprehensive review of the software, including independent verification, stress testing, and a formal search for race conditions or other timing-related defects. None of these steps occurred. AECL’s continued insistence that overdoses were impossible allowed the machine to remain in clinical use and contributed directly to the subsequent accidents.

Ignoring a single incident was a professional failure; ignoring a pattern was a separate and flagrant ethical misstep. Each missed opportunity represented a moment in which AECL could have fulfilled its obligations to public welfare, transparency, and professional responsibility. Instead, these opportunities were neglected, allowing a preventable pattern of catastrophic harm to continue unaddressed.

Due Diligence from Hospitals

AECL did not fulfill its professional obligations as a manufacturer of a safety-critical system, but hospital employees, particularly physicists in charge of overseeing the machines, share culpability for these accidents. Given that the potential cost of misinformation from the manufacturer was human life, the physicists should have exercised more skepticism and done more independent testing. Prior to using their Therac-25, physicists at the Prince Margaret Hospital in Toronto, Canada installed a muzzle that could measure machine output and shut it down in case of malfunction.[4] In taking these precautions, the Prince Margaret Hospital demonstrated supreme professionalism and prevented potential loss of life. In hospitals where incidents occurred, physicists should have put more effort into independent testing. Fritz Hager, a physicist and definition-4 professional at the East Texas Cancer Center, was the only physicist to test Therac-25 rigorously and under the same conditions it had failed in practice. As a result, he was able to demonstrate that the AECL could not claim the incidents were flukes.[4]

Precautions and testing are insufficient without sharing information. Unfortunately, the Prince Margaret physicists' foresight was unique to their hospital. Since there were no incidents at their hospital, they never shared their muzzling idea until March 1986 at the first user group meeting.[4] By March 1986, five of the six incidents had already occurred. Considering that there were only 11 hospitals using the Therac-25 at the time, operators at Kennestone Regional Oncology Center could have contacted other users and shared their information at little cost and with the benefit of saving lives. Further, users could have sooner involved the FDA to expedite regulation and the corrective action plan.

Due Diligence from the Developer

The program for the Therac-25 was developed by a sole engineer. There was no extensive testing done for the implementation of the program, and no integration testing done with the hardware for the Therac-25. As a developer implementing code for a medical machine this powerful, it is crucial that the code is tested. Additionally, the responsibility should never fall on one person. Additional code reviews and testing by others would have significantly reduced the probability of this faulty code being eventually pushed to a production model.

Due Diligence from Regulators

Regulators also bore significant professional responsibility in the Therac 25 incidents. Agencies such as the FDA are charged with enforcing safety standards, evaluating manufacturer claims, and intervening when medical devices pose risks to the public. In this case, regulatory oversight was limited and slow to respond, allowing unsafe conditions to persist far longer than they should have. Early incident reports were accepted largely at face value, and AECL’s explanations were not subjected to the level of independent verification required for a device capable of delivering hazardous radiation doses.

A more rigorous regulatory posture would have included immediate on site investigation after the first incident, mandatory reporting from all hospitals using the machine, and requirements for AECL to perform comprehensive software and hardware safety analyses. Instead, regulatory action came only after multiple overdoses had already occurred and after hospitals pressed for stronger intervention. By the time the FDA compelled AECL to submit a corrective action plan in 1987, six serious accidents had already taken place.

This delay reflects a broader issue: regulators relied too heavily on the manufacturer’s assurances and did not recognize the pattern of harm until it had repeated across different sites. In safety critical domains, professional responsibility includes anticipating the possibility of systemic failure and acting decisively at the first credible sign of danger. The lack of timely regulatory oversight contributed to the continuation of risks that should have been addressed much earlier, and represents another point at which professional diligence fell short.

Professional Analysis

The Therac-25 accidents are often described as failures of software, testing, or management. While accurate, they do not fully capture the ethical significance of the case. Viewed through a professional lens, the Therac-25 illustrates how ethical failure can emerge from the absence of professional judgment at multiple levels of practice. Using a framework that understands professionalism as evolving through several stages, the case reveals shortcomings not only in technical execution, but in how responsibility, judgement, and values were understood and exercised.

This analysis suggests that the Therac-25 was not merely a case of defective technology, but a layered failure of professionalism. At each stage, the demands of professional ethics were only partially met. The cumulative effect of these shortcomings transformed manageable engineering risk into catastrophic human consequences.

Definition 1: Technical Mastery without Ethical Integration

Under the most basic definition, professionalism consists of technical competence and pride in craft. By this standard, AECL demonstrated significant expertise in designing advanced radiation therapy hardware. The Therac-25 incorporated a compact, folded linear accelerator capable of delivering high-energy treatments with precision, reflecting substantial engineering skill.

However, this technical mastery was unevenly applied. Software, which controlled critical safety functions, was treated as a secondary component rather than as a safety-critical infrastructure equivalent to hardware. The reuse of legacy code, minimal documentation, and a lack of formal verification suggest that software engineering was not held to the same professional standards as mechanical design. In this sense, the Therac-25 reflects a narrow conception of technical professionalism that celebrated hardware innovation while failing to treat software as a safety-critical component whose errors could directly endanger patients.

Definition 2: Rule-following Without Judgement

A more developed conception of professionalism emphasizes adherence to formal rules, standards, and procedures. Many actors in the Therac-25 case satisfied this definition in a limited sense. AECL maintained that the machine met its specifications and initially attributed reported injuries to electrical anomalies or operator error. Hospitals relied on manufacturer assurances and followed established operating procedures. Regulators acted within the scope of existing medical device oversight frameworks.

Yet this strict rule-following proved to be insufficient. Each group deferred responsibility by appealing to procedure rather than exercising independent judgment. Error reports were treated as isolated anomalies rather than as warning signs of systemic failure. The ethical weakness here is not from the violation of rules, but in the failure to question whether those rules were adequate given the stakes. The Therac-25 demonstrated how professionalism that is constrained to compliance can obscure emerging risks rather than address them.

Definition 3: Sociotechnical Responsibility

At a more advanced level, professionalism requires recognizing one’s role within a broader sociotechnical system. Under this definition, professionals must consider how design choices, institutional practices, user behavior, and communication structures interact to create or mitigate risk.

The Therac-25 failures illustrate a breakdown at this level. Early overdoses should have prompted a system-wide reassessment involving manufacturers, hospitals, and regulators. Instead, incidents were compartmentalized. Software bugs were treated as technical curiosities, operator actions as isolated mistakes, and injuries as unexplained anomalies. No single actor assumed responsibility for understanding how interface design, software timing, error messaging, and clinical workflow combined to produce harm. The absence of system-level ownership allowed the same failure modes to recur across institutions and over time.

Definition 4: Value-driven Professionalism

The most demanding conception of professionalism emphasizes personal integrity, self-knowledge, and value-driven judgement. Professionals at this level recognize when established practices conflict with fundamental ethical commitments and are willing to halt or challenge work when necessary.

In the Therac-25 case, this form of professionalism is notable largely by its absence. Despite mounting evidence of patient harm, no individual or organization acted decisively to suspend use of the machine until its safety could be assured. There was no clear moment in which a professional asserted that the risks violated their own ethical standards and required immediate intervention. The lack of such value-driven leadership allowed technical uncertainty, institutional inertia, and deference to authority to override concern for patient welfare.

Implications for Professionalism

The Therac-25 accidents demonstrate how ethical failure in professional practice can occur without malicious intent or overt rule-breaking. The machine’s design flaws, software errors, and misleading interface were serious technical problems, but they became catastrophic only through a broader failure of professional judgement across institutions. Engineers, managers, hospital staff, and regulators each acted within limited roles, yet no actor assumed responsibility for evaluating the system as a whole once evidence of patient harm began to emerge.

This case shows that technical sophistication alone does not constitute professionalism. The reliance on software to replace hardware safety interlocks, the dismissal of early incident reports, and the treatment of repeated overdoses as isolated anomalies reveal a pattern in which compliance and expertise were allowed to substitute for ethical reflection. Professionals satisfied formal requirements, but failed to ask whether those requirements were adequate given the stakes involved.

Viewed through a professional lens, the Therac-25 case underscores the importance of system-level responsibility and value-driven judgment in safety-critical fields. When human lives depend on complex technologies, professionalism demands more than adherence to procedure; it requires skepticism, transparency, and the willingness to halt or challenge work when warning signs appear. The case is defined by the absence of Definition 4 Professionalism: no individual or institution asserted a value-driven moral boundary that would have stopped treatment until patient safety could be assured. The lesson of the Therac-25 is not simply a software failure, but a professional failure that occurred when no one was prepared to say that continuing as usual is ethically unacceptable.

References

Where this page came from

This page was imported from Wikibooks. From “Professionalism” on Wikibooks, by its contributors, under CC BY-SA 4.0. Changed here: set as a page; navigation and edit links left out; each image under its own licence, credited in its caption.

Nobody has written it yet — it is the source material at a new address, which is why search engines are asked to skip it and why no one earns from it. It is up for grabs: take it on, and it is yours to rewrite and to earn from.

I disse publikationerProfessionalism

SprogEnglish

Licens: CC BY-SA 4.0 · Bearbejdet efter en.wikibooks.org

Visninger

Kommentarer

Spinner Logo
Version: 2CC0 1.0 (offentligt eje)
The runaway star that left the Tarantula Nebula
Version: 2CC0 1.0 (offentligt eje)
The Blackwell School, where segregation had no law behind it
Version: 2CC0 1.0 (offentligt eje)
The Eagle Nebula, seen in the infrared
Version: 2CC0 1.0 (offentligt eje)
The house where the Equal Rights Amendment was written
Version: 2CC0 1.0 (offentligt eje)
The Aleutians, the forgotten front of the Second World War
Version: 2CC0 1.0 (offentligt eje)
The Cosmic Cliffs are not cliffs