My Account List Orders Book Page

The Therac-25 Disasters

Table of Contents

  • Introduction
  • Chapter 1 The Dawn of Medical Linear Accelerators
  • Chapter 2 From Hardware to Software: The Genesis of the Therac-25
  • Chapter 3 Atomic Energy of Canada Limited and the Promise of Automation
  • Chapter 4 The Illusion of Safety: The Software-Only Interlock Design
  • Chapter 5 Marietta, Georgia: The First Silent Failure
  • Chapter 6 Tyler, Texas: The Nightmare in the Treatment Room
  • Chapter 7 Anatomy of a Bug: The Race Condition and the Cursor Key
  • Chapter 8 Yakima, Washington: The Arithmetic Overflow and the Second Flaw
  • Chapter 9 The Human Toll: Voices of the Victims and Their Families
  • Chapter 10 The Wall of Denial: AECL’s Initial Responses
  • Chapter 11 Enter Nancy Leveson: Investigating the Unthinkable
  • Chapter 12 The FDA Steps In: Regulating Software as a Medical Device
  • Chapter 13 Deconstructing the Code: Inside the PDP-11 Assembly Language
  • Chapter 14 The Myth of "User Error" in Complex Systems
  • Chapter 15 Engineering Blindspots: Why Unit Testing Failed to Find the Bugs
  • Chapter 16 The Recall and the Mandated Redesign
  • Chapter 17 Hardware Backups: Resurrecting the Physical Interlocks
  • Chapter 18 System Safety vs. Software Reliability
  • Chapter 19 The Birth of Modern Software Quality Assurance
  • Chapter 20 Liability, Ethics, and the Responsibility of the Programmer
  • Chapter 21 The Legacy of Therac-25 in the Medical Device Industry
  • Chapter 22 Beyond Medicine: Lessons for Aerospace, Automotive, and Nuclear Software
  • Chapter 23 The Evolution of Safety-Critical Software Standards
  • Chapter 24 Teaching Therac-25: How a Tragedy Became Academic Canon
  • Chapter 25 Twenty-First Century Vulnerabilities: Are We Safer Today?

Introduction

In the mid-1980s, the field of oncology stood on the precipice of a revolution. The introduction of computer-controlled radiation therapy promised unprecedented precision in the fight against cancer. At the vanguard of this technological leap was the Therac-25, a state-of-the-art dual-mode linear accelerator developed by Atomic Energy of Canada Limited. Boasting a highly automated interface, the Therac-25 was designed to deliver targeted, life-saving radiation doses with speed and efficiency. By replacing traditional physical safety mechanisms with software code, its creators believed they had engineered a machine that was not only more elegant, but inherently safer. It was a triumph of modern engineering—until the machine began to deliver lethal doses of radiation to the very patients it was built to heal.

Between 1985 and 1987, the Therac-25 malfunctioned in clinics across North America, administering massive overdoses that were up to a hundred times the intended therapeutic amount. These were not mere therapeutic mishaps; they were catastrophic system failures that caused horrific internal burns, excruciating pain, permanent disfigurement, and, in several cases, agonizing deaths. The victims were ordinary people—grandfathers, mothers, and young adults—who walked into clean, modern treatment rooms expecting healing, only to be struck down by an invisible, silent assailant. For months, the cause of these tragedies remained a mystery, obscured by corporate denial, bureaucratic inertia, and a fundamental misunderstanding of the nature of software.

At the heart of the Therac-25 disaster lay a profound paradigm shift in how human beings interact with machines. Previously, safety was a matter of physical interlocks: copper switches, lead shields, and mechanical gears that physically prevented a machine from operating in a dangerous state. By shifting these responsibilities to a DEC PDP-11 computer and a few thousand lines of assembly code, the developers of the Therac-25 inadvertently introduced a new class of vulnerability. They fell victim to the illusion of software infallibility, believing that because code does not wear out or rust, it cannot fail. This book is the definitive, step-by-step account of how microscopic flaws in that code—specifically a race condition triggered by a fast-typing operator and an arithmetic overflow in a single-byte counter—bypassed all safety protocols and turned a medical miracle into a deadly weapon.

The Therac-25 Disasters is more than a technical autopsy of a famous software bug; it is a human drama and a historical turning point. This narrative traces the journey from the optimistic dawn of medical automation to the harrowing moments inside the treatment rooms of Marietta, Georgia, Tyler, Texas, and Yakima, Washington. It explores the painful battle fought by victims and their families, the courageous investigative work of medical physicists and researchers like Dr. Nancy Leveson, and the regulatory reckoning that forced the FDA and the global engineering community to completely redefine how software is built, tested, and regulated. Through this investigation, computer science was forced for the first time to confront its immense responsibility for human life.

For the modern reader, this book serves as both a gripping historical chronicle and an urgent warning. Today, we live in a world governed by algorithms. Software manages our pacemakers, pilots our commercial aircraft, steers our autonomous vehicles, and regulates our nuclear power grids. The lessons of the Therac-25 are not relics of the floppy-disk era; they are the foundation of modern software safety, highlighting the critical distinction between software reliability and system safety. By understanding how these historic failures occurred, programmers, engineers, healthcare professionals, and everyday technology users will gain invaluable insight into the invisible systems that shape our lives—and learn how we must design them to ensure that the machines we build to serve us never turn against us.


CHAPTER ONE: The Dawn of Medical Linear Accelerators

At the midpoint of the twentieth century, the field of oncology was engaged in a brutal, uphill battle against an enemy that had plagued humanity for millennia. Cancer, characterized by its relentless and chaotic cellular division, resisted most conventional medical interventions. Surgery was the oldest and most direct weapon, yet its efficacy was limited to localized, accessible tumors that had not yet shed microscopic seeds into the surrounding lymph nodes or bloodstream. The knife, however sharp, could not follow the invisible migration of malignant cells without destroying the patient in the process. Medicine desperately needed a non-invasive scalpel, a force that could penetrate deep inside the human body and selectively destroy diseased tissue while leaving the surrounding healthy structures intact.

The scientific community found this invisible force in ionizing radiation. The discovery of X-rays by Wilhelm Röntgen in 1895, followed quickly by Henri Becquerel’s discovery of radioactivity and Marie and Pierre Curie’s isolation of radium, had ignited a medical revolution. Early practitioners quickly realized that these mysterious rays possessed the power to shrink tumors. By exposing malignant growths to radiation, they could induce a cellular arrest, halting the division of cancerous tissues. Yet, these early successes were severely constrained by the physical limitations of the technology available at the time.

The primary tool of early radiation therapy was the conventional X-ray tube, a device that operated on principles not unlike those found in diagnostic imaging today. These early therapeutic units, operating at electrical potentials of fifty to one hundred and fifty kilovolts, produced what physicists call orthovoltage, or "soft" X-rays. While these rays were energetic enough to penetrate the superficial layers of the skin, they lacked the raw power necessary to reach deep-seated tumors, such as those in the lungs, esophagus, or pelvis.

The physics of radiation absorption presented a cruel paradox to early oncologists. As X-rays pass through matter, their intensity decreases exponentially with depth. For soft, low-energy X-rays, the maximum dose of radiation is deposited at the very surface of the skin. By the time the beam travels several centimeters into the body, its energy is largely spent, leaving only a fraction of the therapeutic dose to reach a deep tumor. To deliver a lethal dose to a deep-seated malignancy using orthovoltage equipment, clinicians had to subject the patient’s skin to horrific levels of radiation. This resulted in severe radiation dermatitis, agonizing skin ulcerations, and necrotic burns that often proved as debilitating as the cancer itself. Doctors were forced to choose between undertreating the tumor or literally burning through the patient to reach it.

The quest to overcome this biological and physical barrier led physicists and engineers to seek ways of generating much higher energies. They needed "megavoltage" radiation—beams with energies of one million electron volts or more. At these extreme energy levels, the physics of radiation interaction change in a way that is highly advantageous for clinical treatment. High-energy photons do not deposit their maximum energy at the surface of the skin. Instead, due to a phenomenon known as the skin-sparing effect, the maximum dose is deposited several millimeters, or even centimeters, beneath the surface. This allowed clinicians to spare the sensitive outer layers of skin while delivering a devastating, concentrated dose deep within the torso.

In the search for megavoltage radiation, the mid-twentieth century saw the rise of two competing technological solutions. The first was the cobalt-60 teletherapy unit, which emerged in the early 1950s. These machines utilized a highly radioactive isotope of cobalt, manufactured in nuclear reactors, as a steady source of high-energy gamma rays. Cobalt units were simple, rugged, and remarkably reliable. They required no complex electrical systems to generate radiation; they simply housed a physical capsule of cobalt-60 inside a heavy lead-and-tungsten shield, opening a shutter to allow a beam of gamma rays to emerge. For decades, the cobalt machine was the workhorse of radiation clinics worldwide, providing a dependable means of deep-tissue therapy.

However, cobalt-60 had its own inherent limitations. The isotope decays naturally over time, with a half-life of roughly 5.27 years, meaning that treatment times had to be continuously adjusted and lengthened as the source weakened, and the expensive radioactive core had to be periodically replaced and safely disposed of. Furthermore, the radiation from cobalt-60 is limited to a fixed energy level of approximately 1.25 million electron volts. While this was a massive improvement over orthovoltage X-rays, it still fell short of the energies needed to treat very deep or highly resistant tumors with optimal precision. The beam also suffered from a physical penumbra, a fuzzy, scattered edge that made it difficult to shield delicate, nearby organs from unwanted exposure.

The second solution, and the one that would ultimately transform the landscape of modern medicine, was the medical linear accelerator, or "linac." Rather than relying on the natural decay of a radioactive isotope, a linear accelerator is an active electrical machine that generates high-energy radiation on demand. It does this by accelerating subatomic particles—specifically electrons—to speeds approaching the speed of light, and then directing those particles either directly at the patient or into a heavy metal target to produce high-energy X-rays.

The core technology of the linear accelerator was born out of the crucible of wartime radar research and early high-energy particle physics. During World War II, intense research into microwave radar systems led to the development of the magnetron and the klystron, high-power vacuum tubes capable of generating high-frequency radio waves. Physicists quickly realized that these intense microwave fields could be used to propel charged particles down a straight path. By feeding microwaves into a precision-engineered copper tube known as a waveguide, they could create electromagnetic waves that particles could "surf" like a beachcomber on an ocean swell.

The mechanical design of a medical linear accelerator is a marvel of classical physics and high-precision engineering. Inside the machine, an electron gun—essentially a highly advanced version of the heated filament found in an old television tube—boils off a cloud of free electrons. These electrons are injected into the waveguide, where they are buffeted by powerful microwaves generated by a klystron. As the electrons travel down the length of the evacuated copper tube, the internal geometry of the waveguide causes them to accelerate faster and faster, gaining kinetic energy with every millimeter of travel.

By the time the electrons reach the end of the waveguide, they are traveling at relativistic speeds, packed with millions of electron volts of energy. At this point, the machine must decide how to utilize this high-energy particle beam. In a medical linac, this decision defines the two primary modes of operation: electron mode and photon mode.

In electron mode, the raw beam of accelerated electrons is directed straight out of the machine and toward the patient. Because electrons are charged particles with a relatively large mass compared to photons, they have a finite and predictable range in human tissue. They travel a certain distance into the body, deposit their energy rapidly, and then stop completely. This makes electron therapy ideal for treating superficial or shallow tumors, such as skin cancers, lymph nodes near the surface, or chest wall recurrences, where the clinician wants to avoid damaging deeper structures like the lungs or heart.

In photon mode, the objective is to treat deep-seated tumors. To achieve this, the raw electron beam is not allowed to exit the machine directly. Instead, it is steered into a target made of a high-density metal, such as tungsten. When the high-velocity electrons crash into this target, they undergo a violent deceleration. According to the laws of electromagnetism, when a charged particle rapidly loses velocity, it emits bremsstrahlung, or "braking radiation." This process converts the kinetic energy of the electrons into a highly penetrating beam of high-energy X-rays, or photons. These photons can penetrate deep into the human body, reaching the most inaccessible tumors with minimal surface damage to the patient.

However, this dual-mode capability introduces an enormous physical challenge. An electron beam consists of charged particles that repel one another, and when it exits the vacuum of the waveguide, it tends to remain relatively narrow and highly concentrated. If this narrow, pencil-like beam of raw electrons were to strike a human patient directly, it would deliver an intensely concentrated, lethal dose of radiation to a microscopic area, destroying the tissue completely.

To make the electron beam clinically useful, it must be spread out evenly over a wider treatment area. In early linear accelerators, this was accomplished using a physical device called a scattering foil. The scattering foil is a thin sheet of metal, often made of lead or aluminum, placed directly in the path of the narrow electron beam. As the electrons pass through this foil, they bounce off the metal atoms, scattering in all directions and creating a wide, uniform, and clinically safe beam that can cover a tumor of several centimeters in size.

Conversely, when the machine is operating in photon mode, the opposite problem occurs. When the electron beam strikes the tungsten target, the resulting X-rays are not distributed evenly; they are highly concentrated in the center of the beam, creating a sharp spike in intensity along the central axis. To make this beam clinically useful, physicists designed a physical object known as a flattening filter. The flattening filter is a cone-shaped piece of metal, thick in the middle and thin at the edges, placed in the path of the X-ray beam. The thick center of the filter absorbs more radiation than the thin edges, flattening the energy profile and creating a uniform, level field of radiation across the entire treatment area.

The difference in energy levels required for these two modes is staggering. Because the process of converting electrons to photons through a tungsten target is highly inefficient—most of the energy is lost as heat—the machine must run its internal electron beam at a incredibly high current and intensity when in photon mode to produce a clinically useful dose of X-rays. Typically, the raw electron beam current in photon mode is several hundred times greater than the electron beam current used for direct electron therapy.

This vast difference in intensity represents the central hazard of dual-mode linear accelerators. If the machine were to be configured with its internal electron beam running at the high current required for photon mode, but the tungsten target and the flattening filter were accidentally left out of the path of the beam, the patient would be exposed to the raw, unattenuated electron beam at full intensity. This is not a therapeutic dose of radiation; it is a catastrophic, instantly lethal blast of energy capable of destroying human tissue in seconds.

To prevent such an occurrence, early linear accelerators relied on robust, physical safety systems known as hardwired interlocks. These were mechanical and electrical systems designed to ensure that the machine could never operate in an unsafe configuration. In these early designs, the physical components of the treatment head—including the scattering foils, the tungsten target, and the flattening filters—were mounted on a heavy, movable metal turntable.

The position of this turntable was physically linked to electrical switches and copper relays. If the operator selected an electron treatment, the turntable had to physically slide into the position that placed the scattering foil in the beam path. Only when the turntable was physically seated in the correct position would a metal tab depress an electrical microswitch. This switch completed an electrical circuit, allowing the power to flow to the electron gun. If the turntable was even a millimeter out of place, or if it was aligned for photon mode while the controls were set for electron mode, the circuit remained broken. The machine was physically incapable of generating radiation.

These mechanical interlocks were simple, clumsy, and heavy, but they possessed a fundamental virtue: they failed safely. If an electrical relay broke, it broke the circuit, and the machine shut down. If a wire was severed, the current stopped, and the radiation ceased. There was no ambiguity, no middle ground, and no way for a subtle logic error to bypass the physical reality of a open copper switch.

Throughout the 1960s and 1970s, as these linear accelerators became more common in major medical centers, they revolutionized the treatment of cancer. Survival rates for diseases like Hodgkin's lymphoma, pediatric leukemia, and localized prostate cancer began to climb. The machines were operated by highly trained technicians who worked in tandem with medical physicists and oncologists. The process of setting up a patient was manual, tactile, and deliberate.

An operator would enter the treatment room, physically rotate the heavy gantry of the accelerator, slide the appropriate physical blocks and collimators into place to shape the beam, and manually verify that the turntable was aligned. They would then walk out of the room, close a heavy concrete shield door, and operate a control console that was connected directly to the machine's internal electronics via thick bundles of copper cables.

As the technology matured, however, a new force was beginning to reshape the landscape of engineering: the microprocessor. In the late 1960s and early 1970s, computers were transitioning from massive, building-sized mainframes used by governments and universities to smaller, more affordable minicomputers. Engineers across all disciplines began to look at these digital processors with a sense of immense excitement and possibility. To many, the computer represented the ultimate tool for efficiency, automation, and precision.

In the medical field, this technological optimism was particularly intense. Linear accelerators were becoming increasingly complex, requiring more precise beam shaping, dynamic dosing, and rapid patient throughput to meet the growing demand for cancer care. The manual setup of a linear accelerator was time-consuming. An operator had to manually adjust dozens of physical parameters for every


This is a sample preview. The complete book contains 27 sections.