A Systems Approach to Reducing Human Error in a GP Manufacturing Operation
Chapter Two – Analyzing and Mitigating the Risks of Human Errors
Rob Ahern, Valley Contax Director of Operations
Shortly after taking off from Jorge Chávez International Airport in Lima Peru on midnight on October 2nd, 1996, the pilots of Aeroperú Flight 603 declared an emergency. Their normally reliable flight instruments in the cockpit of their Boeing 757-200 Passenger Jet were displaying all manner of nonsensical readings. The automated alert systems of the plane reacted to the strange instrument readings and sent numerous warnings to the pilots of various (and often contradictory) emergency conditions. Now over the Pacific Ocean in near total darkness, the pilots - responsible for the lives of 70 passengers and crew onboard - were suddenly faced with confusion and uncertainty about the actual air speed and altitude of the plane.
The pilots sought help from local air traffic control to understand their location, altitude, and air speed. But neither the pilots nor the air traffic controller understood that the information displayed on the controller’s screen originated from the plane’s transponder, which was transmitting the same erroneous readings the pilots were receiving on their instrument panel. Believing they were at a safe altitude, the pilots attempted to return the plane safely to the airport. Tragically, they did not return. The plane crashed into the ocean in the dead of night, ending the lives of all 70 people on board Aeroperú Fight 603.
Portions of the underwater wreckage of the Boeing 757-200 were found and recovered, and investigators quickly reached a horrifying realization – an airport employee had accidentally left strips of duct tape over the static ports on the aircraft fuselage. The blockage of these ports had caused the failure of multiple flight instruments during the fateful flight. That employee was identified, and many felt that he was responsible for the accident.
Others argued that the pilots were negligent because they failed to notice the blocked static ports during their pre-flight inspection. Others would lay blame with Boeing because the static port system of the 757-200 was designed to be covered with duct tape during cleaning of the aircraft. Comparable aircraft had been designed with a system of maintenance covers for these ports, which are generally a bright color and carry “Remove Before Flight” flags. Should Boeing have also designed into their flight controls system a master indicator for the possibility of the blockage of these ports? Could that have helped the pilots understand the nature of the erratic instrument readings and warnings and allowed them to react appropriately (e.g., change their focus to the radar altimeter and proximity alarm systems that were operating normally).
Ultimately, Boeing reached a legal settlement with the families of the victims of this accident. The airport employee was controversially convicted in a Peruvian Court of negligent homicide and sentenced to a 2-year suspended sentence. Even the lead accident investigator argued that the individual employee was relatively uneducated and had little understanding of the issue, and that responsibility for the accident was not his alone.
This horrific accident demonstrates the potential severity of a human error. It also illustrates that a single human error is rarely the sole cause of a problem. There are upstream causes and/or contributions to the point of the human making the error – and these causes are often errors of omission during the processes of product design, risk management, and manufacturing and operational process controls. There are also downstream mistakes that can cause the human error to remain undetected and lead to an accident.
In the contact lens manufacturing industry, the consequences of a human error can also be severe, leading to a product defect that could result in a patient experiencing a serious adverse event. As medical device manufacturers, we must perform accurate and complete risk analysis of the hazards that are associated with our products. And this risk analysis must happen at all levels of product realization – from design and development to manufacturing to quality control to packaging and shipping.
The Aeroperú Flight 603 accident illustrates how a series of mistakes, including errors of omission, can result in a disaster caused by human error. The crash could have likely been prevented if, in the design phase, Boeing had recognized that the process of covering static ports with duct tape during fuselage cleaning was inherently problematic. It could have been possibly prevented if Boeing had integrated into their flight control systems a discrete warning that indicated blockage of these ports, and provided the pilots with an effective checklist to manage this emergency condition. If the operating airline had more effective process controls and training, perhaps the crash could have been prevented. If the pilots had noticed the duct tape was still present over the static ports during the pre-flight inspection of the aircraft, the accident would have been prevented – but this is also a function of the original design flaw to not include easily identifiable covers. And finally, the accident could have been prevented if the individual airline employee followed the procedural requirement to remove the duct tape before flight.
CLMA LEAN Committee Member Manny Carvalho (BostonSight Director of Lab Operations) describes the potential for accidents and failures occurring in complex and often highly regulated systems as the Swiss Cheese Theory. The Aeroperú Fight 603 accident exemplifies that the human error is truly the culmination of a series of flaws at different layers within a highly controlled system. Each piece of stacked Swiss cheese represents a layer of defense intended to prevent an error from being made, remaining undetected, and being significant enough to cause a serious event. With the Swiss Cheese Theory, the error could have been prevented at any one of the layers of cheese, but in this case at least one hole aligned in each layer of the stacked Swiss cheese, which allowed the hazard to pass through all the layers of protection that were in place to guard against the serious event. The take-away here is that it’s not just about preventing the error itself – we also need an appropriate number of layers of defense, and we need those layers to be as solid as possible.
For medical device manufactures, this is a call 1) accurately identify and analyze our hazards to understand what those hazards are and which of them have the potential to result in a serious or catastrophic outcome if a mistake is made or undetected; and 2) we must follow through with our risk management processes and effectively mitigate those serious risks to as low of a probability and severity as possible. That mitigation needs to include improvements at many levels of an organization, from product design and labeling to operational process controls and employee training, through quality control and packaging, and even basic quality assurances processes, i.e., how effectively an organization monitors and documents customer feedback and then makes the necessary improvements that address the root cause of the problem in order to prevent a future disaster.
Written by:
Rob Ahern
Valley Contax Operations Director