CSB Investigation — Fire & Explosion
BP-Husky Toledo Refinery Naphtha Release and Fire
BP / Husky Energy
📍 Oregon, OH
Incident Date: September 20, 2022  |  CSB Report Released: June 2024
2
Fatalities
1
Injuries
$597M
Property Damage
Naphtha
Chemical / Hazard
📋 Incident Summary

On September 20, 2022, a massive naphtha release and fire at the BP-Husky Toledo Refinery in Oregon, Ohio, killed two BP employees who were brothers, and seriously injured one other worker. Over 23,000 pounds of naphtha — a highly flammable liquid hydrocarbon — were released from a pressurized vessel, forming a vapor cloud that ignited and caused a flash fire. The fire burned for four hours and caused approximately $597 million in property damage, ultimately leading to the permanent closure of the refinery.

The incident unfolded during a complex process upset. The fuel gas system became overwhelmed, liquid hydrocarbons backed up into equipment not designed to handle liquid, and a pressurized vessel overflowed with naphtha. During the four hours preceding the naphtha release, the control room experienced more than 3,700 alarms — an alarm flood that completely overwhelmed the operator team ability to diagnose and respond to the developing upset.

The CSB found that the alarm management system at BP-Husky was severely deficient. Alarm rationalization, prioritization, and suppression were inadequate, resulting in an unmanageable flood of alarms during the process upset. The CSB issued seven recommendations targeting alarm management, process upset response, and operator decision-making support.

🔎 Key Findings
Finding 1
Alarm Flood of 3,700+ Alarms in 12 Hours
The control room experienced over 3,700 alarms in the 12 hours preceding the naphtha release — making it impossible for operators to identify and prioritize the critical process deviation driving the incident.
Finding 2
Fuel Gas System Liquid Accumulation
Liquid hydrocarbons accumulated in the fuel gas system during the complex process upset, ultimately causing the vessel overflow that released the naphtha vapor cloud.
Finding 3
Two Brothers Killed in Flash Fire
Two BP employees who were brothers were fatally injured when the naphtha vapor cloud ignited. Both were in proximity to the release area, reflecting inadequate evacuation procedures during the developing process upset.
Finding 4
$597 Million in Property Damage
The fire caused approximately $597 million in property damage, ultimately resulting in the permanent shutdown and demolition of the facility.
Finding 5
Refinery Permanently Closed
The extent of the damage led to the permanent closure of the BP-Husky Toledo Refinery following the fire.
Finding 6
"Nearly Everything That Could Go Wrong Did Go Wrong"
CSB Chairperson Steve Owens characterized the incident as a scenario where multiple simultaneous failures — process, instrumentation, alarm management, and personnel response — combined to produce a catastrophic outcome.
🔍 Root Causes
1
Alarm Management System Failure — Alarm Flood
The fundamental failure was the alarm management system inability to provide meaningful, prioritized information during a complex process upset, rendering operators unable to diagnose or respond effectively.
2
Fuel Gas System Liquid Accumulation Hazard
The fuel gas system was susceptible to liquid accumulation during process upsets in a way not managed by operating procedures or engineering safeguards.
3
Complex Process Upset Without Adequate Response Capability
The combination of a complex process upset, alarm flood, and inadequate operator guidance left the team without effective means to diagnose and correct the situation before naphtha release.
4
Deficient Emergency Response During Process Upset
Personnel remained in proximity to the developing hazard during the hours-long alarm event, reflecting inadequate emergency mustering or evacuation triggers during process upsets.
☑ CSB Recommendations
→ Ohio Refining Company
Implement a comprehensive alarm management program in accordance with ISA-18.2 (Management of Alarm Systems for the Process Industries), including alarm rationalization, prioritization, and flood reduction.
→ Ohio Refining Company
Develop and implement abnormal situation management procedures providing operators with clear decision guidance during complex process upsets, including defined escalation and evacuation triggers.
→ API
Update API 754 (Process Safety Performance Indicators) to include alarm management system performance as a leading process safety indicator.
→ ISA
Develop updated implementation guidance for ISA-18.2 specifically addressing complex process upset scenarios and alarm flood prevention during cascading equipment failures.
💡 Lessons Learned
⚠ Alarm management is a process safety system, not a nuisance management problem. An alarm system that floods operators with thousands of alarms during an upset provides no useful information at the exact moment it is most needed.
⚠ Complex process upsets require operators to diagnose and respond under time pressure. Alarm systems, operating procedures, and decision support tools must be designed for upset management, not just steady-state monitoring.
⚠ When a process upset develops over hours and alarms are flooding in, defined escalation triggers — including mandatory evacuation of non-essential personnel from the affected area — are required safety provisions.
⚠ The permanent loss of a major refinery and two lives was the consequence of an alarm management system failure. Alarm rationalization, prioritization, and flood management are among the most impactful process safety investments a facility can make.
⚠ PSM elements — especially PHA, SOP for abnormal situations, and training on complex upset recognition — must address multi-failure scenarios, not just single-cause events.
PSM Elements: PHA · SOP · TRN · MI · EP
🔨 Safety Meeting Toolbox Talk
Topic: Alarm Management & Abnormal Situation Response
💬Does our facility have a formal alarm management program following ISA-18.2, including documented alarm rationalization for all process alarms?
💬What is the maximum number of alarms our operators receive per hour during normal operations? During process upsets? Do we have alarm flood limits and management plans?
💬Do we have defined escalation triggers during process upsets — including mandatory evacuation of non-essential personnel from potentially affected areas?
💬Are operators trained specifically on abnormal situation management and complex process upset response, beyond routine steady-state and alarm response training?
💬Do our operating procedures for abnormal situations provide clear diagnostic guidance and decision support — not just alarm setpoints and normal operating targets?
✎ Team Action Items
✓Pull an alarm report for your unit from the past 30 days and count the number of alarms per hour — verify your alarm rate is within industry benchmarks (less than 10 per hour average)
✓Review alarm rationalization records for your unit — confirm all process alarms have documented rationalization including setpoint basis and appropriate operator response time
✓Identify the escalation and evacuation trigger conditions in your unit abnormal situation management procedures — verify they are defined, trained, and exercised
✓Review your fuel gas or utility system operating procedures for abnormal operations and confirm liquid accumulation scenarios are specifically addressed with defined operator actions
🔗 PSM Failures Behind This Incident

This incident traced to breakdowns across 5 PSM elements (PHA · SOP · TRN · MI · EP). Each represents a documented gap that process safety documentation and consulting can close before a similar event occurs at your facility.

Process Hazard Analysis (PHA)
A structured PHA or HAZOP study exists to identify exactly these scenarios before they occur. When PHA is absent, superficial, or overdue for revalidation, hazards operate unseen until they kill someone.
Supporting documents in our library →
Operating Procedures (SOPs)
Operators cannot reliably hold safe operating limits without clear, current, enforced procedures. Deviation from acceptable operating conditions — a root cause here — is a direct consequence of SOP failure.
Supporting documents in our library →
Training & Operator Competency
Workers must understand process hazards — not just the steps on the page. Training records, refresher frequency, and verified competency are all OSHA PSM requirements that gaps here violated.
Supporting documents in our library →
Mechanical Integrity (MI)
Equipment must be designed, inspected, and maintained to operate safely in its intended service. Mechanical integrity failures — degraded equipment, missed inspections, deferred repairs — contributed to loss of containment here.
Supporting documents in our library →
Employee Participation
OSHA PSM requires workers to be meaningfully involved in hazard analyses and procedure development — not just trained on the finished product. Active participation catches gaps that management alone misses.
Supporting documents in our library →
Process Safety Management Consulting & Document Library
📂
PSM Document Library
32 ready-to-deploy PSM documents covering all 14 OSHA elements — procedures, checklists, and audit templates built for facilities operating under 29 CFR 1910.119.
Browse the Library →
📊
Free PSM Health Score
Find out where your PSM program stands across all 14 OSHA elements. Our free health score surfaces your biggest gaps in under 10 minutes — no account required.
Check Your Score →
📞
Consulting Services
PHA facilitation, PSM program builds, compliance audits, and OSHA inspection support. Transparent flat-fee pricing — no retainer required to get started.
View Pricing →
📋 Explore the full incident library: All 132 CSB Case Studies →