Blinded by the HMI: The Splitter Tower Level Transmitter Failure
A flatlined level transmitter and a failed backup switch combined with an HMI alarm flood led to a catastrophic refinery explosion.
1. The Hook (Flashpoint)
At 1:20 PM, a massive, earth-shaking explosion ripped through the isomerization unit of a major petroleum refinery, sending a towering plume of black smoke into the air. The blast destroyed surrounding infrastructure, shattered windows miles away, and tragically claimed the lives of 15 workers while injuring 180 others in one of the worst industrial disasters in modern history.
2. The Setup
The isomerization unit startup had begun during the night shift, but operations had been delayed. By mid-morning, the incoming day shift operators were dealing with a complex, non-routine startup under intense pressure to restore production. The control room environment was chaotic; operators were fatigued, and the SCADA/HMI screens were saturated with an “alarm flood”—over 100 active and stale alarms that created a wall of visual noise.
The primary equipment involved was the raffinate splitter tower, a 170-foot-tall distillation column. Because it was startup, the tower was being filled with highly flammable liquid hydrocarbons. To monitor the liquid level inside the column, operators relied on a displacer-type level transmitter, which displayed the level as a percentage (0% to 100%) on their HMI screen. A backup independent high-level switch was installed on the tower to trip the feed pumps if the level exceeded a critical threshold, but it had not been functional or calibrated for several years.
3. The Breakdown
- The Startup Fill: Operators began pumping liquid hydrocarbon feed into the bottom of the splitter tower, which required heating the liquid to initiate distillation.
- The Instrument Flatline: As the liquid level rose, the displacer-type transmitter became physically stuck due to mechanical internal build-up and a calibration discrepancy. The HMI display flatlined, showing a constant level of roughly 8 feet (approx. 50% capacity).
- The Blind Operations: Relying entirely on the flatline HMI display and believing the level was stable, operators continued to pump in fresh feed while applying heat to the tower bottom.
- The High-Level Overflow: Because the level transmitter was stuck and the backup safety high-level switch failed to activate, the liquid level inside the 170-foot tower rose unchecked until it completely filled the column and began overflowing into the overhead vapor line.
- The Ignition: Flammable liquid and vapor filled the overhead piping, overwhelmed the low-capacity blowdown drum, and erupted out of the vent stack like a geyser. The resulting massive vapor cloud drifted across the unit and was ignited by a idling diesel truck engine nearby, triggering the devastating explosion.
4. Interactive Quiz
Guess the Root Cause
Why did the operators continue pumping liquid into the splitter tower despite it being dangerously full?
5. The RCA
Direct Cause: The direct cause of the explosion was the overfilling of the raffinate splitter tower, which led to a massive release of flammable hydrocarbons out of the blowdown stack, creating a vapor cloud that found an ignition source.
Systemic/Human Cause: The root cause was a systemic failure in process safety management, instrument maintenance, and control system design. The facility safety culture tolerated critical safety devices—specifically the independent backup high-level switch—being out of service for years. Furthermore, the control HMI was designed without “rate-of-change” drift alarms that would flag a flatlined instrument during active filling, and operators were overwhelmed by an alarm flood, preventing them from recognizing the danger.
6. Failure Modes and Effects Analysis (FMEA)
(Note: FMEA rendering to be completed by Claude editorial agent prior to publication).
7. Applicable Codes & Standards
- ISA-84 / IEC 61511 — Functional Safety: Safety Instrumented Systems for the Process Industry Sector. Requires independent protection layers (IPLs) to be maintained and tested.
- API RP 551 — Process Measurement Instrumentation: Outlines design and installation practices for level measurement, highlighting the need for redundant, diverse technologies (e.g., radar + displacer) for high-level safety trips.
- ANSI/ISA-18.2 — Management of Alarm Systems for the Process Industries: Defines alarm management lifecycle, targeting the elimination of alarm floods and “chatter” to ensure operators can identify critical alarms.
- OSHA 29 CFR 1910.119 — Process Safety Management (PSM) of Highly Hazardous Chemicals: Mandates strict mechanical integrity programs for safety-critical instruments.
- API RP 754 — Process Safety Performance Indicators for the Refining and Petrochemical Industries.
8. Free Resource
[Lead magnet CTA — Claude]
Download the Level Instrumentation & Alarm Safety Checklist
9. Actionable Takeaways
- Implement Diverse Level Redundancy: For safety-critical vessels, never rely on a single technology. Combine different measurement physics (such as a guided wave radar alongside a mechanical displacer) to prevent common-mode mechanical failures.
- Implement Rate-of-Change and Flatline Audits: Program control system logic to automatically detect flatlining instruments. If a level transmitter signal remains mathematically constant for a defined period during filling operations, trigger a diagnostic fault alarm.
- Enforce Alarm Management Lifecycles: Audit and clean up SCADA alarm configurations. Ensure the control room meets ISA-18.2 standards, keeping the average alarm rate below 1 alarm per 10 minutes, preventing operator alarm fatigue.
10. Conclusion
When a control screen lies and safety switches are ignored, a 170-foot column of fuel becomes a silent bomb waiting for a spark.

Community Discussion
Join the conversation. What are your thoughts on this incident or safety topic?
Comments will appear here once the Giscus GitHub repository is linked.