Skip to main content

Why Software Quality Matters

eweek.com Perhaps nothing shows the ravages of faulty calculations as clearly as cancer.

The patients who were suffering in Panama had cancers of the pelvis. Pelvic organs such as the intestines and kidneys are acutely sensitive to radiation. Before a cancer patient such as Garcia is exposed to radiation, a doctor devises a treatment plan that determines what dose of radiation can safely be directed at the tumor. The physician considers the tumor's position and depth in the body, the likelihood that the cancer has spread to surrounding tissue, the location and sensitivity of nearby organs and the best angles of attack.

As part of the plan, the doctor figures out how to place metal shields, known as "blocks," above the area where the tumor is located. These blocks, usually made of lead or a metal alloy called cerrobend, protect normal or sensitive tissue from the gamma rays to come.

The doctor hands his plan to a medical physicist, who feeds information on the size, shape and location of the blocks into a software package. These packages generally create a 3-D picture of how the dose will be distributed, showing how the radiation will "sum" as beams coming in from different angles intersect at depth in the patient's tissue. Once the doctor prescribes a dosage, the software calculates the duration of treatment.

The physicists in Panama were carrying out a doctor's instruction to be more protective, adding a fifth block to the four the hospital often used on patients in cancer treatments. The extra block could help protect patients whose tissues were especially sensitive due to previous surgeries or radiation treatments.

Multidata's planning software was designed to calculate treatments when there were four or fewer blocks, according to the company's general business manager, Mick Conley. Saldaña, however, read Multidata's manual and concluded she could make the software account for a fifth block.

According to an August 2001 report from the IAEA, Saldaña found the software didn't only work if she entered the dimensions of each block individually, up to four. She found it also allowed her to enter the dimensions of all five blocks as a single, composite shape-for instance, a rectangle with one triangular block sitting in each corner and a fifth square block protruding, tooth-like, down into the rectangle from the top.

PointerWant the story latest news in programming environments and developer tools? Check out eWEEK's Developer Center at http://developer.eweek.com

So, using the mouse attached to her computer, she entered on the screen the coordinates of the specially shaped block— first the inner perimeter of the shape and then the outer perimeter. This is when she felt she was "home free."

After all, when Saldaña entered the data for this unusual-looking block, the system produced a diagram that appeared to confirm its dimensions. She seemed to be getting confirmation from the system itself that her approach was acceptable.

Next Page: Ravages of miscalculation. But inside the software, the calculations of appropriate dosages were going awry. The treatment time would be close to correct if Saldaña entered the data for the inner perimeter of the shape going in one direction, say clockwise, and the outer perimeter in the opposite direction, according to the IAEA report. But if she entered the data for the inner and outer perimeters going in the same direction, so that the two loops defining the perimeters crossed, the software essentially locked up. It was not able to accurately recognize the shape and, as a result, miscalculated the treatment times, the report said.

Depending on how many treatments the patients received, they accumulated overdoses ranging from 20 percent more radiation than was prescribed to a double dose of the potentially harmful rays, the IAEA found.

Inspectors from the FDA were dispatched to Multidata's offices after the agency received reports of patient "radiation overexposures." The inspection ran from May 31 to Sept. 21, 2001.

A summary of their findings echoed the IAEA report: "The treatment-planning system miscalculated the dose each patient was to receive due to failure of the software to correctly handle certain types of blocks... This resulted in a much higher dose being calculated for each patient."

Multidata's Conley says the FDA's finding "is wrong." He says that if you read FDA reports, "you find out the FDA isn't always right.

"Given [the input] that was given," he says, "our system calculated the correct amount, the correct dose. It was an unexpected result. And, if [the staff in Panama] had checked, they would have found an unexpected result."

Conley insists his company has done nothing wrong. He says the physicists at the National Cancer Institute never called Multidata asking for advice or support.

The physicists admit they did not always verify the results of the software's calculations, which Multidata's manual said was "the responsibility of the user."

Saldaña says the hospital was treating more than 100 patients per day using the one Cobalt-60 machine. The IAEA also found that whatever steps the hospital took to ensure the radiation machine was operating properly only addressed the hardware. There was no quality-assurance program for the software-or its results.

In the day-to-day operations of the cancer institute, that meant the physicists were not required to tell anyone they had changed the way they entered data into the cancer-therapy system. As a result, no one on staff questioned the software's results.

Had the hospital verified the dosages, by manually checking the software's calculations or by testing the dosages in water before radiating patients, a procedure that Conley argues is standard medical practice in much of the rest of the world-the staff would have caught the overdoses in time to avoid harming anyone.

But independent experts not associated with the case say software that controls medical equipment and other life-critical devices should be designed to pause or shut down if told to execute a task it's not programmed to perform.

"If a computer can make a user kill people, it's like a loaded gun," says Jack Ganssle, an engineer whose Ganssle Group advises companies and developers on how to create high-quality software. "A user shouldn't be able to do anything that causes a machine to be dangerous."

But the Multidata software continued to operate.

Next Page: Cause of death.
As tragic as it is, the Panama incident does not stand alone. In all, Baseline has found no fewer than a half-dozen cases in which software has contributed to loss of life. (See Eight Fatal Software-Related Accidents, Baseline, March 2004.)

Comments

Popular posts from this blog

New York Post Online Edition

news : "December 29, 2003 -- WASHINGTON - Startling new Army statistics show that strife-torn Baghdad - considered the most dangerous city in the world - now has a lower murder rate than New York. The newest numbers, released by the Army's 1st Infantry Division, reveal that over the past three months, murders and other crimes in Baghdad are decreasing dramatically and that in the month of October, there were fewer murders per capita there than the Big Apple, Chicago, Los Angeles and Washington, D.C. The Bush administration and outside experts are touting these new figures as a sign that, eight months after the fall of Saddam Hussein, major progress is starting to be made in the oft-criticized effort by the United States and coalition partners to restore order and rebuild Iraq. 'If these numbers are accurate, they show that the systems we put in place four months ago to develop a police force based on the principles of a free and democratic society are starting to

The Jodie Lane Project Responds to City Council Testimony

The Jodie Lane Project : New York, NY -- February 12, 2004. The City Council Transportation Committee held a hearing today to investigate the causes of Jodie S. Lane’s tragic electrocution death on January 16th. The testimony revealed a startling lack of oversight on the part of the Public Services Commission, charged with overseeing Con Edison’s compliance with the National Electric Safety Code, last revised in 1913. With only 5 inspectors at their disposal, the Public Services Commission relies entirely on Con Edison to report safety problems. Because Con Edison only reports incidents resulting in injury or death, the PSC was aware of only 15 shock incidents in the last 5 years. Con Edison has acknowledged that it actually received 539 reports of shock incidents in the same period, effectively admitting to misleading the PSC by an order of magnitude. It is not only this discrepancy that is alarming, but also the fact that the Public Services Commission, charged with ensuring