⚡ Blog Mission: Transforming past incidents into actionable insights to prevent future accidents.
Incident Report

Blinded by the HMI: The Splitter Tower Level Transmitter Failure

A flatlined level transmitter and a failed backup switch combined with an HMI alarm flood led to a catastrophic refinery explosion.

Blinded by the HMI: The Splitter Tower Level Transmitter Failure

1. The Hook (Flashpoint)

At 1:20 PM, a massive, earth-shaking explosion ripped through the isomerization unit of a major petroleum refinery, sending a towering plume of black smoke into the air. The blast destroyed surrounding infrastructure, shattered windows miles away, and tragically claimed the lives of 15 workers while injuring 180 others in one of the worst industrial disasters in modern history.

2. The Setup

The isomerization unit startup had begun during the night shift, but operations had been delayed. By mid-morning, the incoming day shift operators were dealing with a complex, non-routine startup under intense pressure to restore production. The control room environment was chaotic; operators were fatigued, and the SCADA/HMI screens were saturated with an “alarm flood”—over 100 active and stale alarms that created a wall of visual noise.

The primary equipment involved was the raffinate splitter tower, a 170-foot-tall distillation column. Because it was startup, the tower was being filled with highly flammable liquid hydrocarbons. To monitor the liquid level inside the column, operators relied on a displacer-type level transmitter, which displayed the level as a percentage (0% to 100%) on their HMI screen. A backup independent high-level switch was installed on the tower to trip the feed pumps if the level exceeded a critical threshold, but it had not been functional or calibrated for several years.

3. The Breakdown

  1. The Startup Fill: Operators began pumping liquid hydrocarbon feed into the bottom of the splitter tower, which required heating the liquid to initiate distillation.
  2. The Instrument Flatline: As the liquid level rose, the displacer-type transmitter became physically stuck due to mechanical internal build-up and a calibration discrepancy. The HMI display flatlined, showing a constant level of roughly 8 feet (approx. 50% capacity).
  3. The Blind Operations: Relying entirely on the flatline HMI display and believing the level was stable, operators continued to pump in fresh feed while applying heat to the tower bottom.
  4. The High-Level Overflow: Because the level transmitter was stuck and the backup safety high-level switch failed to activate, the liquid level inside the 170-foot tower rose unchecked until it completely filled the column and began overflowing into the overhead vapor line.
  5. The Ignition: Flammable liquid and vapor filled the overhead piping, overwhelmed the low-capacity blowdown drum, and erupted out of the vent stack like a geyser. The resulting massive vapor cloud drifted across the unit and was ignited by a idling diesel truck engine nearby, triggering the devastating explosion.

4. Interactive Quiz

? Guess the Root Cause

Why did the operators continue pumping liquid into the splitter tower despite it being dangerously full?

5. The RCA

Direct Cause: The direct cause of the explosion was the overfilling of the raffinate splitter tower, which led to a massive release of flammable hydrocarbons out of the blowdown stack, creating a vapor cloud that found an ignition source.

Systemic/Human Cause: The root cause was a systemic failure in process safety management, instrument maintenance, and control system design. The facility safety culture tolerated critical safety devices—specifically the independent backup high-level switch—being out of service for years. Furthermore, the control HMI was designed without “rate-of-change” drift alarms that would flag a flatlined instrument during active filling, and operators were overwhelmed by an alarm flood, preventing them from recognizing the danger.

6. Failure Modes and Effects Analysis (FMEA)

(Note: FMEA rendering to be completed by Claude editorial agent prior to publication).

FMEA Table for the Splitter Tower Level Transmitter Failure Incident

7. Applicable Codes & Standards

  • ISA-84 / IEC 61511 — Functional Safety: Safety Instrumented Systems for the Process Industry Sector. Requires independent protection layers (IPLs) to be maintained and tested.
  • API RP 551 — Process Measurement Instrumentation: Outlines design and installation practices for level measurement, highlighting the need for redundant, diverse technologies (e.g., radar + displacer) for high-level safety trips.
  • ANSI/ISA-18.2 — Management of Alarm Systems for the Process Industries: Defines alarm management lifecycle, targeting the elimination of alarm floods and “chatter” to ensure operators can identify critical alarms.
  • OSHA 29 CFR 1910.119 — Process Safety Management (PSM) of Highly Hazardous Chemicals: Mandates strict mechanical integrity programs for safety-critical instruments.
  • API RP 754 — Process Safety Performance Indicators for the Refining and Petrochemical Industries.

8. Free Resource

[Lead magnet CTA — Claude]

Download the Level Instrumentation & Alarm Safety Checklist

9. Actionable Takeaways

  • Implement Diverse Level Redundancy: For safety-critical vessels, never rely on a single technology. Combine different measurement physics (such as a guided wave radar alongside a mechanical displacer) to prevent common-mode mechanical failures.
  • Implement Rate-of-Change and Flatline Audits: Program control system logic to automatically detect flatlining instruments. If a level transmitter signal remains mathematically constant for a defined period during filling operations, trigger a diagnostic fault alarm.
  • Enforce Alarm Management Lifecycles: Audit and clean up SCADA alarm configurations. Ensure the control room meets ISA-18.2 standards, keeping the average alarm rate below 1 alarm per 10 minutes, preventing operator alarm fatigue.

10. Conclusion

When a control screen lies and safety switches are ignored, a 170-foot column of fuel becomes a silent bomb waiting for a spark.

Post Conclusion
Failure Mode — Do Not Ignore This post describes a failure mode or active hazard. Do not ignore the warning signs described.

Community Discussion

Join the conversation. What are your thoughts on this incident or safety topic?

Comments will appear here once the Giscus GitHub repository is linked.

ELI CRITICALITY SCALE

Likelihood × Consequence Risk Matrix

Every post on this blog is classified using this industrial risk matrix. Badge colors map directly to the resulting criticality level.

Full Guide →
Likelihood ↓ / Consequence → Minor Moderate Serious Fatal
Almost Certain L1 L2 L3 L3
Likely L0 L1 L2 L3
Possible L0 L0 L1 L2
Unlikely L0 L0 L0 L1
Badge Key
L0
Normal
Educational / correct practice
L1
Advisory
Near-miss / equipment damage
L2
Warning
Serious injury potential
L3
Critical
Fatality / catastrophic failure