Human Factors EngineeringNuclear SafetySystems Safety

The Three-Mile Island Human Error Analysis – A field of study following the event

An exhaustive academic exploration of human error analysis, cognitive ergonomics, and systems safety methodologies developed following the 1979 Three Mile Island incident.

memjavad
PUBLISHED
Scientifically Reviewed · Dr. Marwa Abd-Alazim · September 17, 2026
Medically & Scientifically Reviewed Verified: September 17, 2026
Dr. Marwa Abd-Alazim Ph.D.
Professor of Psychology University of Kerbala
Review Criteria & Clinical Standards

This content undergoes rigorous scientific peer-review and medical editorial standards at Arab Psychology Network to ensure clinical accuracy, validity, and compliance with evidence-based guidelines from leading psychological and healthcare authorities (APA / WHO).

At 4:00:37 AM on March 28, 1979, the Unit 2 reactor at the Three Mile Island (TMI-2) Nuclear Generating Station near Middletown, Pennsylvania, experienced an automatic shutdown that would irrevocably shatter the twentieth century’s technocratic assumptions regarding nuclear safety. Within less than two minutes, a sequence of secondary-loop fluid disturbances, compounded by unseated mechanical valves and obscured control room feedback, initiated the most severe commercial nuclear accident in United States history. Yet, the definitive crisis of TMI-2 was not an unmitigated triumph of mechanical entropy over structural engineering; the reactor vessel and containment systems ultimately withstood catastrophic core melting and prevented massive atmospheric release. Instead, the incident exposed a profound epistemological crisis: an absolute disconnect between the deterministic assumptions of industrial systems engineering and the psychological, cognitive, and ergonomic realities of human operators executing tasks under dynamic, high-stakes uncertainty.

Before the events at Londonderry Township, industrial safety paradigms remained overwhelmingly anchored in Newtonian, component-level reliability metrics. Nuclear installations were conceptualized as deterministic conglomerates of redundant mechanical, electrical, and structural systems. If pipe thicknesses satisfied code, if safety injection pumps possessed dual redundancies, and if operators strictly executed step-by-step procedures, severe accidents were deemed statistically impossible within design-basis planning envelopes. Human beings within these systems were viewed reductively as predictable, quasi-mechanical relays—individual components expected to transduce meter readings into procedural interventions without cognitive friction. When operational deviations manifested, the immediate post-war engineering culture reflexively pathologized operator intervention, framing operational breakdowns through the narrow lens of operator error, procedural non-compliance, and individual negligence.

The protracted, multi-day disaster at TMI-2 destroyed this mechanistic fiction. It demonstrated that human operators do not malfunction in isolation; rather, they perform within deeply coupled socio-technical architectures where opaque interface ergonomics, contradictory instrumentation, institutional blindness, and rigid procedural dogma systematically conspire to induce cognitive failure. The forensic post-mortems of Three Mile Island catalyzed an intellectual diaspora, precipitating the birth of contemporary Human Factors Engineering (HFE), Cognitive Systems Engineering (CSE), Second-Generation Human Reliability Assessment (HRA), and High Reliability Organizing (HRO). Analyzing the human error dynamics of Three Mile Island is therefore not an exercise in historical retrospection; it is the study of the foundational event that fundamentally redefined how modern science conceptualizes the nexus between human cognition, organizational dynamics, and catastrophic technological risk.

1. Historical Genesis and Chronology of the Three Mile Island Unit 2 Incident

1.1 Mechanical Initiators Versus Operator Interventions

The physical sequence of events initiating the TMI-2 incident began not within the nuclear island itself, but in the mundane, secondary balance-of-plant systems. In an attempt to dislodge resin blockage within one of the eight deep-bed condensate polishers, operators inadvertently introduced demineralized water into the station’s compressed instrument air lines. This moisture intrusion led to a complete pneumatic failure across the condensate polishing discharge valves, which abruptly slammed shut at 4:00:37 AM. The instantaneous cessation of feedwater flow to the secondary side of the two once-through steam generators (OTSGs) caused an automatic trip of the main condensate pumps and, sequentially, the main turbine. Within seconds, the heat sink responsible for removing thermal energy from the pressurized water reactor’s primary coolant loop evaporated, initiating an abrupt, dangerous surge in primary system temperature and pressure.

In response to this rapid overpressurization, the reactor automatically tripped via control rod insertion within eight seconds. Simultaneously, an electromatic pilot-operated relief valve (PORV) mounted atop the reactor’s primary pressurizer lifted as designed at 2,255 pounds per square inch gauge (psig) to vent primary steam and arrest the pressure spike. Coincident with this expected safety transient, auxiliary feedwater (AFW) pumps started automatically to re-establish the secondary heat sink. However, both emergency AFW block valves (valves EF-V-12A and EF-V-12B) were mechanically shut, tagged out during maintenance operations days prior, and inadvertently left closed in direct violation of the plant’s operational technical specifications. Deprived of both main and emergency feedwater, the OTSGs rapidly boiled dry, leaving the primary system with zero secondary cooling capacity.

The mechanical initiator shifted into a catastrophic socio-technical divergence when the PORV, having opened to relieve pressure, failed to reseat when primary system pressure dropped below its operational threshold of 2,205 psig. Instead of mechanically snapping closed, the valve remained stuck wide open, creating an unmonitored path of fluid egress directly into the reactor coolant drain tank. The fatal operational rupture lay within the control room’s Human-Machine Interface (HMI). A status indicator light on Panel 4 illuminated not to confirm the physical, mechanical position of the valve stem, but merely to indicate that electrical power had been de-energized from the actuation solenoid. The operators, observing the extinguishment of this command signal light, formed an absolute, unshakeable mental model: they believed the PORV was closed.

This critical divergence between the physical state of the plant and the operators’ internal cognitive model persisted for two hours and twenty-two minutes. Physical reality diverged exponentially from operational belief. While the operators executed standard reactor trip protocols under the assumption that the primary system was intact and merely experiencing secondary-side thermal fluctuations, the reactor was actively hemorrhaging coolant at thousands of pounds per minute. Every manual intervention executed by the control room crew over the subsequent critical hours was predicated on this fundamentally flawed diagnostic premise—an erroneous mental model engineered directly by ambiguous, misleading instrumentation.

1.2 The Evolution of the Loss-of-Coolant Accident

Because the stuck-open PORV allowed primary coolant to continuously escape while the reactor remained depressurized, the event transformed from an anticipated operational transient into an unrecognized, unmitigated small-break loss-of-coolant accident (SBLOCA). As primary coolant mass rapidly escaped through the open PORV into the containment building basement, the primary system pressure plummeted toward the saturation point of the water. At approximately 1,600 psig, the automated High-Pressure Injection (HPI) system, a foundational component of the Emergency Core Cooling System (ECCS), automatically engaged, forcing hundreds of gallons per minute of borated water into the reactor coolant system to compensate for the lost inventory.

At this juncture, the operational crew committed the single most fateful intervention of the disaster: they manually throttled the HPI pumps down to a negligible trickle and completely deactivated one of them. This action, widely condemned in initial post-accident reviews as gross operator negligence, was in truth the direct consequence of contradictory physical indicators clashing with strict procedural mandates. In Babcock & Wilcox (B&W) pressurized water reactors, operators were heavily trained to prevent the pressurizer from “going solid”—a hazardous hydraulic condition wherein the steam bubble at the top of the pressurizer collapses entirely, filling the vessel completely with liquid. Because water is essentially incompressible, a solid pressurizer can lead to catastrophic, instantaneous pressure spikes capable of rupturing the primary pressure boundary.

Operators observed that the indicated water level inside the pressurizer was rising rapidly, approaching the upper threshold of the scale. What the instrumentation obscured was the underlying two-phase thermal-hydraulic phenomenon: primary loop depressurization had caused bulk boiling within the core and reactor vessels. Large steam voids were forming within the reactor vessel upper head and core regions, expanding dynamically and pushing the remaining liquid water upward through the surge line into the pressurizer. The pressurizer was reading high not because the reactor coolant system was flooded, but because it was being violently displaced by steam voids generated by an uncovered, boiling core.

Operating under the deterministic procedural rule to avoid a solid pressurizer at all costs, the crew intervened to suppress inventory replenishment just as the plant required it most. With the high-pressure emergency cooling choked off and the PORV still venting primary fluid, the core underwent rapid uncovery. By 6:00 AM, the upper two-thirds of the nuclear fuel assemblies were exposed to superheated steam. Deprived of convective liquid cooling, the Zircaloy fuel cladding reached temperatures exceeding 1,800 degrees Fahrenheit, initiating an autocatalytic, highly exothermic zirconium-water reaction. This chemical reaction severely oxidized and embrittled the fuel cladding, releasing millions of curies of fission products into the primary coolant loop and generating immense volumes of volatile hydrogen gas, which would subsequently migrate into the reactor building and detonate thirty-two hours later in an unrecognized containment pressure spike.

1.3 Early Institutional Attribution to Operator Blame

The immediate narrative construct assembled by the commercial nuclear industry, regulatory bodies, and mass media was swift, punitive, and classic in its reductionism: the accident at Three Mile Island was the fault of human operators who failed to follow procedures. Within hours of the initial diagnostic stabilization, utility executives from Metropolitan Edison and representatives from the Nuclear Regulatory Commission (NRC) held press conferences that systematically laid proximate blame on the operational crew for manually overriding the automated emergency cooling systems.

This early attribution dynamic exemplifies the “bad apple” paradigm of human failure, as critiqued extensively decades later by safety scientists such as Sidney Dekker. By isolating the operators’ decision to throttle the HPI pumps from the cognitive, architectural, and ergonomic environment in which the decision was made, institutions insulated themselves from structural accountability. The dominant line of inquiry did not initially ask why the operators believed the plant was solid, or what instrument signatures prompted their behavior; rather, the regulatory apparatus focused strictly on the divergence between the operators’ manual actions and the prescribed step-by-step algorithms detailed within the plant’s Emergency Operating Procedures (EOPs).

Engineering bodies within the vendor apparatus, notably Babcock & Wilcox, initially aligned behind this mechanistic micro-attribution. The technical narrative posited that the physical machinery had operated within theoretical design parameters: the reactor had tripped on demand, the safety valves had opened to relieve overpressurization, and the emergency core cooling systems had initialized automatically precisely when system thresholds were breached. In this narrow formulation, the machine was pristine, and the human was the defective, unpredictable component that corrupted an otherwise robust engineering system. This refusal to adopt a holistic socio-technical causal model delayed the recognition of catastrophic systemic vulnerabilities that were endemic across the entire civilian nuclear fleet, preserving institutional equilibrium at the expense of empirical scientific truth.

2. The Kemeny and Rogovin Inquiries: An Epistemological Paradigm Shift

2.1 Findings of the President’s Commission on the Accident at Three Mile Island

Recognizing the deep public mistrust and regulatory confusion surrounding the disaster, President Jimmy Carter established the President’s Commission on the Accident at Three Mile Island on April 11, 1979, chaired by mathematician and Dartmouth College President John G. Kemeny. The resulting Kemeny Commission Report, published in October 1979, delivered a blistering indictment of the institutional and cognitive systems governing commercial nuclear power, fundamentally dismantling the simplistic “operator error” hypothesis.

The philosophical fulcrum of the Kemeny Commission’s findings was articulated in an iconic declaration: “The equipment was at least good enough; the people were not properly prepared.” Kemeny and his investigators established that the disaster was not fundamentally an engineering hardware failure, but an institutional, intellectual, and organizational collapse. The report systematically revealed that the operational crew at TMI-2 had been thrust into a catastrophic scenario for which they had received zero meaningful pedagogical preparation, operating interfaces that were violently incompatible with human cognitive processing, and adhering to procedures that were actively misleading.

Crucially, the Kemeny inquiry unmasked a chronic pattern of institutional silence and regulatory suppression regarding precursor events. Eighteen months prior to TMI-2, in September 1977, the Davis-Besse nuclear plant in Ohio—also utilizing a Babcock & Wilcox pressurized water reactor—experienced an identical transient: an electromatic PORV stuck open, the control room indicator erroneously signaled closure based on solenoid de-energization, the pressurizer level indicated high despite coolant loss, and operators manually throttled high-pressure injection. In the Davis-Besse event, an alert engineer realized the valve was stuck after twenty minutes, averting core damage. Despite internal memoranda authored by B&W engineers (the Kelly-Dunn and Hallman memos) explicitly warning that operators at other sites would throttle HPI and cause a core meltdown if the interface and procedures were not modified, the warnings were systematically buried within corporate hierarchies and never disseminated to utilities or licensed operating crews.

2.2 The Rogovin Special Inquiry and Institutional Blindness

Simultaneously, the Nuclear Regulatory Commission commissioned an independent internal post-mortem, led by attorney Mitchell Rogovin. The Rogovin Special Inquiry Group Report (NUREG/CR-1250) delivered an even more devastating critique of the regulatory architecture, diagnosing the NRC as an agency ossified by bureaucratic inertia, fragmented programmatic oversight, and a total intellectual blindness toward the operational realities of nuclear control rooms.

Rogovin laid bare the structural flaws of the commercial nuclear regulatory framework, which had spent three decades obsessing almost exclusively over catastrophic, “large-break” loss-of-coolant accidents—such as the instantaneous, double-ended guillotine rupture of a massive 36-inch reactor coolant main loop pipe. Regulators and design engineers had constructed elaborate, deterministic, automated safety systems to combat these rare, high-energy hardware destructions. In contrast, they had almost totally neglected the subtle, complex, and far more statistically probable operational dynamics of small-break LOCAs, transient management, and protracted human-system interaction.

The Rogovin report formalized the catastrophic conceptual bifurcation that existed between hardware reliability and total system performance. It concluded that an engineering methodology that treats the human operator as an external, post-hoc appendage to a mechanical infrastructure is fundamentally invalid. Rogovin proved that the TMI-2 operators were operating within an operational vacuum engineered directly by regulatory negligence: their training simulators were incapable of modeling two-phase thermal-hydraulic physics; their operational procedures were legally mandated to be event-based rather than symptom-oriented; and the regulatory inspections conducted by the NRC completely ignored the human factors design of control room annunciators, gauges, and spatial layouts.

2.3 From Micro-Attribution to Macro-Systemic Failure

The synthesis of the Kemeny and Rogovin inquiries catalyzed a historic epistemological shift in safety science and technological accident analysis. By definitively invalidating the micro-attribution model—which isolated proximate operator actions as the root cause of systemic catastrophes—these inquiries established the modern doctrine of macro-systemic failure. Proximate operator actions ceased to be viewed as the initiating cause of an accident; instead, they were recognized as the final downstream consequence of deep, latent organizational, ergonomic, and cultural pathologies embedded within the system years prior to the event.

This epistemological transition mirrored and accelerated the theoretical work of emerging safety philosophers. It decoupled the operational act from the proximate etiology of technical failure, laying the groundwork for what British psychologist James Reason would later formalize as the “Swiss Cheese Model” of accident causation. In this emergent framework, accidents require the dynamic, catastrophic alignment of multiple latent conditions: organizational design oversights, flawed management directives, inadequate operational training, ambiguous interface designs, and systemic institutional silence.

Ultimately, the inquiries post-TMI mandated that human performance could no longer be treated as an independent variable within technological systems. Instead, human performance was recognized as an emergent, dependent output of system design. If an operator misdiagnoses a critical thermodynamic condition because the physical instrumentation displays contradictory data and operational procedures demand inappropriate intervention, the failure resides firmly within the socio-technical architecture, not the biological entity executing the interface commands.

3. Control Room Ergonomics and Interface Deficiencies at TMI-2

3.1 The Annunciator Avalanche and Sensory Saturation

The physical environment of the TMI-2 control room on the morning of March 28 was an ergonomic nightmare that directly induced sensory saturation and cognitive paralysis. Within the first minute of the secondary transient, more than one hundred distinct alarm annunciators illuminated across the expansive, vertical control boards. Within several minutes, this figure expanded to over two hundred active visual alarms, accompanied by a continuous, deafening auditory cacophony of chimes, bells, horns, and buzzers. The sheer sensory deluge utterly overwhelmed the operational crew’s capacity for physiological and neurological attention processing.

The station was devoid of any centralized alarm filtering, prioritization matrices, or hierarchical triage displays. A critically urgent warning signaling low primary system pressure or high containment sump levels was visually and acoustically identical to an alarm indicating a mundane, benign condition, such as a localized ventilation filter differential pressure or a secondary wastewater tank level deviation. In this state of acoustic and visual chaos, the operators were subjected to profound “cognitive tunneling.” When human sensory processing channels are completely saturated by unprioritized, high-frequency alerts, the physiological stress response forces attention into an ultra-narrow focus, drastically degrading peripheral situational awareness and rendering the holistic synthesis of disparate dynamic parameters neurologically impossible.

The operators spent critical early minutes not formulating diagnostic hypotheses regarding two-phase flow physics, but desperately engaging in physical triage: running along the panels attempting to silence auditory horns, manually acknowledging flashing backlight tiles, and attempting to discern which flashing alarm among dozens of identical square plastic panels represented the primary initiating transient. The interface effectively transformed the operators into reactive biological switch-silencers rather than proactive, systemic monitors.

3.2 Spatial Dislocation and Ambiguous Instrumentation

The control board architecture at TMI-2 suffered from catastrophic spatial dislocation and interface ambiguity, heavily influenced by an archaic layout methodology that grouped components strictly by electrical vendor classifications rather than operational cognitive workflows. Critical physical indicators were widely separated from their associated control actuators. An operator adjusting a secondary valve on one control panel was completely blind to primary system pressure indicators located thirty feet away on a perpendicular panel board, requiring constant physical traversing of the control room floor to cross-correlate fundamental thermodynamic parameters.

The most egregious interface failure lay in the design of the PORV position indicator on Panel 4. The dashboard featured an illuminated indicator that signaled the operator that the valve was “Closed.” However, the sensor loop was not wired to any mechanical limit switch on the valve stem itself, nor to an acoustic monitor on the relief line. The light circuit was wired exclusively to the electrical coil of the actuation solenoid. When electrical power to the solenoid was interrupted, the light extinguished, communicating an authoritative but entirely false reality: the human-machine interface signaled that the valve was mechanically seated, when in truth the valve plug was physically stuck in the wide-open position. The instrumentation displayed intent of command rather than actual state of the physical plant.

Furthermore, critical secondary indicators that could have shattered the operators’ false mental model were spatially obscured, uncalibrated, or scaled inappropriately. A direct temperature sensor located on the discharge pipe downstream of the PORV—which read nearly 300 degrees Fahrenheit, an absolute confirmation of continuous high-pressure steam leakage—was positioned on a rear auxiliary panel, entirely outside the primary operator sightlines. When an operator finally walked behind the panel to inspect this thermocouple, the reading was dismissed because that specific valve was historically known to have a baseline “weeping” leak, and the gauge lacked any operational dynamic trending to indicate that the temperature had dramatically escalated to saturation levels. Similarly, the primary core-exit thermocouples (CETs), which later recorded temperatures exceeding 2,000 degrees Fahrenheit as the fuel rods began to liquefy, were dismissed by operators because the computerized data logger printed the values as question marks or maximum-scale gibberish; the instrumentation scale had been artificially capped at 700 degrees Fahrenheit, under the myopic engineering assumption that operational core temperatures would never exceed design-basis parameters.

3.3 Early Human-Machine Interface (HMI) Analysis Methodologies

The catastrophic ergonomic layout of TMI-2 forced the rapid emergence of formalized Human-Machine Interface analysis methodologies within the nuclear sector. Prior to the accident, control room design reviews were conducted purely through electrical and spatial drafting paradigms. If components satisfied basic separation criteria and terminal blocks were accessible for maintenance, the interface was legally certified. TMI-2 mandated the immediate birth of rigorous physical anthropometric and biomechanical audits across all commercial operating facilities.

In the direct aftermath, human factors engineers pioneered the deployment of visual scan-path tracking and link analysis across physical mimic boards. Researchers mapped the physical steps, head rotations, and eye movements required of operators to execute fundamental emergency sequences. These spatial mapping studies exposed shocking inefficiencies: operators frequently had to crisscross hundreds of square feet of control space to verify interrelated thermodynamic parameters, breaking visual continuity and severely taxing short-term working memory during dynamic plant upsets.

These early diagnostic audits catalyzed the foundational tenets of Ecological Interface Design (EID). Researchers began arguing that nuclear workstations could no longer be designed as collections of discrete, localized instruments. Interfaces had to be constructed around the physical and functional topology of the underlying physical system, visually rendering complex thermodynamic states—such as mass-energy balance spaces and phase-saturation diagrams—directly to the human perceptual apparatus, rather than forcing the operator to manually synthesize dozens of fragmented, spatially dislocated analog meters.

4. Cognitive Overload and Information Processing Under Stress

4.1 Rasmussen’s Skill-Rule-Knowledge Framework Applied to TMI

To rigorously deconstruct the cognitive breakdown of the TMI-2 operational crew, safety scientists increasingly turned to the theoretical architectures of cognitive psychology, most notably the seminal Skill-Rule-Knowledge (SRK) framework developed by Danish cognitive engineer Jens Rasmussen. Rasmussen conceptualized human performance along three hierarchical tiers of cognitive control: highly automated, sensorimotor skill-based actions; execution of learned, procedural “if-then” schemas at the rule-based level; and novel, conceptual thermodynamic deduction at the knowledge-based level when established schemas are exhausted.

When the initial transient struck at 4:00 AM, the operators’ automated, skill-based behavioral routines—honed through thousands of hours of routine baseline plant operations—were instantaneously disrupted. The plant was rapidly pushed outside familiar operational boundaries. The crew reflexively retreated to the rule-based performance tier, attempting to match observed plant parameters to standard procedural execution algorithms. However, the rule-based tier failed completely because the rules provided to the operators were structurally invalid for the specific operational context. The procedures instructed the crew to maintain primary pressure and avoid a water-solid pressurizer at all costs, but the rules assumed that an intact pressure boundary was maintained.

The operators were consequently forced to escalate their cognitive processing to the knowledge-based tier. Under ideal, non-stress conditions, knowledge-based performance is profoundly demanding: it requires human beings to construct an abstract, deep mental model of dynamic, invisible physical processes, running mental simulations of complex thermodynamics based on observed data. Under the acute acoustic terror, high adrenaline, and sensory fragmentation of the TMI-2 control room, the cognitive tax required to deduce spontaneous two-phase fluid mechanics and steam bubble voiding in an obscured reactor vessel was neurologically unsustainable. The operators lacked both the specialized thermodynamic mental frameworks and the uncorrupted observational data required to operate successfully at the knowledge-based level, locking them into an intellectual failure loop.

4.2 Mental Model Formulation and Diagnostic Fixation

The primary cognitive pathology that paralyzed the operational crew was diagnostic fixation, heavily reinforced by acute confirmation bias. Within the opening minutes of the accident, based on the erroneous PORV closed light and the rapidly elevating pressurizer liquid level gauge, the operators formulated a foundational mental model: the reactor coolant system is intact, and the primary loop is going solid with water due to excessive safety injection.

Once this erroneous cognitive hypothesis was established, human psychological processing mechanisms aggressively preserved it. In dynamic environments characterized by high ambiguity and extreme peril, the human brain utilizes confirmation bias not as an act of malice or laziness, but as a vital heuristic mechanism to preserve operational coherence and prevent total psychic overload. Over the subsequent two hours, every piece of incoming sensory data was filtered through the distorting lens of this false mental model. When the pressurizer level continued to climb, the crew saw it as definitive proof that their hypothesis was correct, which led them to throttle HPI even more aggressively.

Conversely, every piece of divergent sensory data that should have invalidated the hypothesis was selectively discounted, rationalized, or outright ignored. When primary system pressure dropped precipitously—a thermodynamic impossibility if the system were truly full of solid, cold liquid water—the operators attributed the drop to minor thermal fluctuations from secondary steam generator boiling. When the reactor coolant pumps began violently vibrating, cavitating, and slamming against their mechanical bearing casings, the operators did not realize that the pumps were attempting to pump two-phase steam-water mixtures; instead, they assumed the pumps were mechanically malfunctioning, and subsequently shut down all four primary coolant pumps, definitively terminating all forced convective heat removal from the reactor core. Every anomalous physical symptom was aggressively retrofitted into their prevailing, catastrophically flawed mental model.

4.3 Physiological Stress and Working Memory Constriction

The cognitive collapse at Three Mile Island was profoundly exacerbated by the neurobiological realities of acute human stress. Under conditions of profound industrial existential crisis—where operators are acutely aware that their immediate physical actions hold life-or-death consequences for millions of surrounding citizens—the human sympathetic nervous system triggers massive catecholamine surges, fundamentally altering cognitive architectures.

Neuropsychological research demonstrated that acute situational panic severely constricts human working memory capacity. The normal human capability to hold and manipulate approximately seven disparate pieces of operational information in working memory decays down to two or three items. Multi-parameter dynamic tracking—the critical cognitive ability to simultaneously monitor secondary heat sinks, primary inventory trends, saturation margins, and containment states—becomes neurologically degraded. The operators experienced severe temporal distortion, losing track of elapsed operational time, which severely warped their ability to calculate dynamic mass-energy balance flow rates.

This stress-induced working memory collapse produced hyper-vigilance leading directly to premature behavioral closure. When faced with an opaque, highly threatening dynamic state, the human mind desperately craves closure—the settling upon a definitive diagnosis that allows the initiation of physical actions. Once the operators achieved this premature closure with the “solid pressurizer” diagnosis, reconsidering alternative, highly threatening failure hypotheses (such as a profound loss-of-coolant accident inside containment) was actively rejected by the cognitive apparatus to stave off overwhelming psychological distress. The biological human component, left unassisted by cognitive-support interfaces, defaulted to survival-driven cognitive short-circuits.

5. Procedural Formalism Versus Dynamic Realities

5.1 The Limits of Prescriptive, Event-Based Procedures

The operational framework governing TMI-2 was fundamentally disabled by an over-reliance on rigid, deterministic, “event-based” Emergency Operating Procedures (EOPs). Prior to 1979, the entirety of commercial nuclear operational doctrine was structured around prescriptive, event-based frameworks. These procedures were designed around a strict diagnostic architecture: the operator was required to accurately identify the specific initiating physical event (e.g., “Steam Line Break,” “Loss of Offsite Power,” “Large-Break LOCA”) within the opening moments of the transient, and then mechanically execute a linear, deterministic “if-then” algorithmic checklist tailored precisely to that single, pre-analyzed event.

The fatal structural vulnerability of event-based procedures lies in their inability to cope with concurrent, compound, unmodeled, or masked failures. If an accident sequence deviates even marginally from the pure, idealized, single-failure scenarios analyzed in the station’s Final Safety Analysis Report (FSAR), the procedural structure collapses. At TMI-2, the event was not a single failure; it was a compound, dynamically mutating crisis involving an auxiliary feedwater valve isolation, an unrecognized PORV mechanical failure, a secondary-to-primary thermal transient, and core voiding. The operators had no single procedure entitled: “Loss of Heat Sink Coupled with an Unrecognized SBLOCA and High Indicated Pressurizer Level.”

Furthermore, the event-based procedures contained deeply embedded operational traps. The standard operating procedure for B&W reactors explicitly and unconditionally mandated: “Do not let the pressurizer go solid.” The procedural formalism failed to communicate the underlying engineering rationale: it prohibited solid water conditions to protect mechanical pressure limits, but it never intended for operators to prioritize this rule over maintaining inventory to protect the core from thermal uncovery. The prescriptive procedure presented rules as absolute, decontextualized mechanical laws, forcing the operators into an algorithmic straightjacket that directly caused core melting.

5.2 Genesis of Symptom-Oriented Emergency Operating Procedures

The conceptual collapse of event-based procedures at TMI-2 forced the most radical doctrinal transformation in the history of nuclear operations: the rapid invention and implementation of Symptom-Oriented Emergency Operating Procedures, also known as Function-Oriented Procedures. Recognizing that human beings cannot reliably diagnose the specific mechanical origin of a complex, compound transient in the midst of cognitive chaos, safety engineers completely inverted the procedural philosophy.

Symptom-oriented procedures abandon the requirement for an immediate, accurate postulation of the underlying root cause. Instead, the procedural architecture is anchored in the continuous, programmatic monitoring and defense of a discrete set of immutable Critical Safety Functions (CSFs). Regardless of whether an event is initiated by a sabotage act, a sheared pipe, an electrical failure, or a stuck valve, the operators’ singular, unambiguous mandate is to systematically stabilize the physical mechanisms that sustain life and structural integrity:

  • Subcriticality (arresting nuclear fission)
  • Core Cooling (maintaining heat removal from the fuel)
  • Reactor Coolant System Integrity (preventing boundary failure)
  • Secondary Heat Sink (maintaining steam generator thermal transfer)
  • Containment Integrity (preventing radioactive atmospheric release)
  • Inventory and Pressure Control (maintaining subcooling margin)

Pioneered through collaborative consortia led by vendor owner groups—including the Westinghouse Owners Group (WOG), Combustion Engineering Owners Group (CEOG), and the Babcock & Wilcox Owners Group (BWOG)—symptom-oriented guidelines utilize robust algorithmic decision trees. If the “Core Cooling” critical safety function is challenged—manifested through the simple, indisputable symptom of lost saturation margin—the procedure directs the immediate, unconditional, manual initiation of maximum high-pressure safety injection, regardless of what the pressurizer water level is indicating. The procedural paradigm shifted from guessing the mechanical identity of the ghost in the machine to the brute-force defense of fundamental thermodynamic boundaries.

5.3 Procedure Ergonomics and Human-Readability Standards

Parallel to the theoretical shift toward symptom-based frameworks was an urgent revolution in the ergonomics of procedural design and linguistic presentation. Forensic examinations of the operational manuals used at TMI-2 revealed an appalling lack of basic communication engineering. Procedures were presented as dense, unbroken blocks of technical prose, filled with complex, multi-clause conditional sentences, obscure abbreviations, inconsistent labeling that failed to match physical control panel nameplates, and vital cautionary warnings buried deep inside instructional steps.

Post-TMI human factors research led to the formal codification of linguistic complexity metrics and visual ergonomics applied directly to operational documents. Methodologies borrowed from military aviation and behavioral linguistics established that procedures must be designed for execute-ability under acute cognitive degradation. The classic single-text layout was systematically replaced across the commercial nuclear industry by the standardized dual-column formatting system.

In a modern dual-column procedure, the left-hand column specifies concise, unambiguous operational imperatives utilizing standardized verb lexicons (e.g., “VERIFY,” “START,” “CLOSE”). The right-hand column explicitly details the Contingency Actions—the immediate, mandatory alternative steps to take if the primary left-hand action fails or cannot be verified. Furthermore, the nuclear industry introduced rigorous Human Factors Verification and Validation (V&V) protocols: prior to legal certification, all operational procedures must be executed by multiple independent operational crews on high-fidelity, plant-referenced control room simulators under dynamic, degraded states to mathematically prove that the human-procedure interface is cognitively robust, syntactically clear, and physically executable without diagnostic error.

6. The Formal Emergence of Cognitive Systems Engineering (CSE)

6.1 Hollnagel, Woods, and the Joint Cognitive System Concept

The intellectual debris of Three Mile Island provided the fertile ground from which the entirely new discipline of Cognitive Systems Engineering (CSE) emerged in the early 1980s. Led by visionary human factors scholars such as Erik Hollnagel and David D. Woods, CSE was explicitly founded to deconstruct the obsolete Cartesian divide that had plagued traditional industrial engineering—the profound error of treating the technical system (the nuclear reactor) and the human operator (the cognitive agent) as discrete, independently operating entities.

Hollnagel and Woods introduced the revolutionary paradigm of the Joint Cognitive System (JCS). In a JCS, safety and failure are not structural properties residing within the mechanical components or the biological human brain alone; rather, safety is an emergent property generated across the dynamic, interactive boundary between the two. The human and the technological infrastructure form a co-adaptive, tightly coupled cognitive entity that co-regulates processes in the physical world. TMI-2 was the archetypal failure of a Joint Cognitive System: the interface degraded the operator, the operator misdirected the automated systems, and the mechanical plant entered a thermodynamic domain that neither the human nor the automated control loops could comprehend or mitigate.

To explain the systemic degradation of control during such crises, Hollnagel formulated the Contextual Control Model (COCOM). COCOM posits that human control over complex technological dynamics operates along a fluid spectrum governed by the amount of cognitive time available versus the subjective time required to process the situation:

  • Scrambled Control: Zero time, total sensory panic; actions are essentially random, reactive, and driven by instinctual motor responses.
  • Opportunistic Control: Extremely limited time and degraded mental models; operators grab the most salient, immediate cues (e.g., “Pressurizer level is high!”) and execute localized, short-sighted actions without systemic analysis.
  • Tactical Control: Standard procedural execution; planning is short-to-medium range, following established operational schemas.
  • Strategic Control: Full situational comprehension; operators comfortably look ahead, running predictive thermodynamic mental simulations and anticipating future transients.

At TMI-2, the catastrophic confluence of interface deficiencies and sudden thermodynamic voiding violently dragged the operational crew from tactical down to opportunistic and scrambled control, structurally locking them in a behavioral failure spiral.

6.2 Ecological Interface Design and Affordance Theory

The academic fallout of TMI-2 also revolutionized interface design theory, culminating in the formalization of Ecological Interface Design (EID) by Kim Vicente and Jens Rasmussen. Grounded in the perceptual psychology of J.J. Gibson and his concept of “affordances”—the idea that visual environments should inherently communicate the actions they afford—EID established that an industrial interface must not simply present raw, decomposed sensor variables (e.g., primary pressure: 1,200 psig; primary temperature: 560°F). Rather, it must visually project the underlying, higher-order physical and functional invariants of the system directly onto the display.

Vicente and Rasmussen introduced the Abstraction Hierarchy as the engineering framework for modern interface architecture. A complex system must be simultaneously visualized across five distinct conceptual tiers:

  1. Functional Purpose: The ultimate system goals (e.g., prevent core melt, contain fission products).
  2. Abstract Function: The governing thermodynamic conservation laws of mass, energy, and momentum balances.
  3. Generalized Function: The fundamental processes involved (e.g., heat transfer, fluid circulation).
  4. Physical Function: The operational states of individual components (e.g., pump operational, valve open/closed).
  5. Physical Form: The spatial location, structural layout, and physical condition of hardware.

The fatal failure at TMI-2 was that the control room provided interface representations strictly at the lowest tiers: Physical Form and isolated Physical Functions. The operators were presented with a fractured array of hundreds of individual temperature, pressure, and level indicators, leaving the entire burden of mentally computing the Abstract Function—calculating mass-energy conservation to recognize the loss-of-coolant state—entirely upon the biological working memory of the stressed operators. EID solved this structural flaw by pioneering visual state-space displays, such as dynamic saturation curves where a single graphical cursor plotted system pressure directly against temperature relative to the boiling curve. Had a dynamic saturation-margin display existed at TMI-2, the operators would have immediately seen their cursor plunged deep into the red “SUPERHEAT/BOILING” region, shattering the solid-pressurizer illusion within seconds.

6.3 Resilience Engineering Precursors Post-TMI

The systemic analysis of Three Mile Island planted the historical and conceptual seeds for what would evolve into the discipline of Resilience Engineering in the early 2000s. Pioneers in the field, analyzing the transcripts and telemetry of TMI-2, began to observe the profound systemic brittleness inherent in highly complex, highly optimized technological operations. Traditional safety engineering assumed that systemic reliability was achieved by eliminating all human operational variability through rigid standardization, automation, and compliance.

However, TMI-2 proved that static compliance is fundamentally incapable of guaranteeing survival when unexpected, non-linear interactions breach design-basis envelopes. The systems were brittle: they functioned with mathematical precision within narrow operational corridors, but collapsed catastrophically when pushed beyond their design margins. Scholars recognized that the human operator is not merely a liability or a source of operational variability to be eradicated through procedural straightjackets. Rather, the human operator represents the primary, indispensable catalyst of operational resilience—the only component within a complex socio-technical network possessing the biological capacity to adapt, extrapolate, improvise, and actively synthesize novel recovery paths in unanticipated degraded states.

Post-TMI safety science began shifting the intellectual objective of systems engineering. Instead of attempting the impossible task of designing an inherently safe, perfectly deterministic machine that merely uses human beings as compliant switch-throwers, engineering had to design resilient socio-technical architectures. This meant constructing systems that explicitly enhance and amplify the human capacity for adaptive, resilient control—ensuring that when unexpected transients emerge, the combined human-machine system possesses the margin, tolerance, and flexibility to absorb the disruption and reorganize into a dynamically stable state.

7. Advancements in Quantitative Human Reliability Assessment (HRA)

7.1 First-Generation HRA: THERP and ASEP

The stark realization that human actions could fundamentally alter the risk profiles of critical infrastructures triggered an intense imperative to quantify human performance within engineering calculations. This demand led to the rapid maturation of First-Generation Human Reliability Assessment (HRA) methodologies, spearheaded by Alan Swain and his colleagues at Sandia National Laboratories under the sponsorship of the NRC. The crown jewel of this quantitative revolution was the formalization of THERP (Technique for Human Error Rate Prediction), definitively codified in the monumental 1983 publication of NUREG/CR-1278.

THERP approached human cognition through a deeply classical, reductionist engineering methodology. It treated the human operator essentially as an interchangeable, biological mechanical component embedded within a technological circuit. The methodology relied on task analysis to rigorously decompose complex operational procedures into tiny, discrete, atomic behavioral units—such as reading an analog meter, turning a two-position rotary switch, or verifying an annunciator. Each discrete human action was assigned a baseline Nominal Human Error Probability (HEP) derived from empirical laboratory data, expert judgments, and historical industrial observations (e.g., the probability of misreading an analog gauge was tabulated at $p \approx 0.003$).

To account for the real-world operational environment, THERP adjusted these baseline probabilities through the mathematical application of Performance Shaping Factors (PSFs). Analysts multiplied nominal error rates by quantitative stress multipliers, time-pressure coefficients, interface quality factors, and task complexity indices. If a task was executed under acute stress, the nominal HEP was multiplied by an order of magnitude. A simplified derivative methodology, the Accident Sequence Evaluation Program (ASEP), was simultaneously developed to allow rapid, screening-level human reliability calculations in broader probabilistic studies.

Despite its mathematical rigor, First-Generation HRA suffered from crippling epistemological limitations. By treating human cognitive performance as a series of discrete, decomposable, independent actions analogous to the mechanical wear-and-tear failure of valves or electrical relays, THERP completely failed to model higher-order cognitive phenomena. It could mathematically calculate the probability of an operator failing to throw switch “A,” but it was utterly blind to the systemic realities exposed by TMI-2: the formulation of deeply held false mental models, diagnostic fixation, confirmation bias, and the complex social dynamics of control room command teams.

7.2 The Evolution to Second-Generation HRA: ATHEANA and CREAM

Recognizing the profound theoretical deficiencies of first-generation models, human reliability researchers in the 1990s engineered a paradigm shift, constructing Second-Generation HRA methodologies. Chief among these advanced frameworks were ATHEANA (A Technique for Human Event Analysis), developed explicitly by the NRC under NUREG-1624, and CREAM (Cognitive Reliability and Error Analysis Method), pioneered by Erik Hollnagel.

Second-Generation HRA abandoned the reductionist attempt to quantify isolated human action failures. Instead, it positioned the operational context as the supreme, primary causal driver of human behavior. ATHEANA was engineered explicitly around the foundational lessons of Three Mile Island: its primary objective was to identify and model “Error-Forcing Contexts” (EFCs). An Error-Forcing Context is a catastrophic alignment of plant conditions, misleading interface presentations, fragmented operational guidelines, and organizational pressures that systematically conspire to make an erroneous human decision seem entirely logical, rational, and procedurally correct to the operational crew at the moment of execution. ATHEANA shifted the quantitative focus from: “What is the probability that an operator randomly makes an error?” to: “What is the probability that the system enters a context where an intelligent, well-trained human will be cognitively trapped into taking an inappropriate action?”

Similarly, Hollnagel’s CREAM methodology integrated cognitive task dependencies directly into human reliability calculations. CREAM distinguished between observable behavioral manifestations (“phenotypes”) and the underlying cognitive failure modes (“genotypes”), such as memory failures, diagnostic judgment traps, and intention-formation errors. CREAM evaluated human action reliability through the structural lens of the operational context, calculating failure probabilities based on whether the crew was operating in Scrambled, Opportunistic, Tactical, or Strategic control modes. Second-generation methods thus permanently embedded cognitive psychology and interface ergonomics into the mathematical machinery of quantitative safety analysis.

7.3 Integration of HRA into Probabilistic Risk Assessment (PRA)

The operational crisis of TMI-2 fundamentally revolutionized the deployment of Probabilistic Risk Assessment (PRA) throughout the global nuclear enterprise. Prior to 1979, PRA was an academic, highly theoretical discipline, typified by the controversial 1975 Reactor Safety Study (WASH-1400 / NUREG-75/014, or the “Rasmussen Report”). WASH-1400 had modeled nuclear accidents almost entirely through mechanical and electrical fault tree and event tree system architectures, heavily discounting human-system interactions during dynamic transients.

Post-TMI, the regulatory apparatus recognized that a PRA model devoid of sophisticated human reliability integration is functionally worthless for predicting real-world systemic catastrophic risk. Nuclear facilities were mandated to execute systematic, exhaustive Individual Plant Examinations (IPEs), synthesizing HRA directly into event-tree accident progressions. High-Pressure Melt Scenarios (HPMS) were systematically re-evaluated, not through the passive lens of unmitigated mechanical pipe ruptures, but through the dynamic lens of post-initiator human interventions—such as the manual deactivation of emergency cooling systems based on ambiguous instrumentation.

In modern nuclear engineering, PRA event-tree branch points are deeply populated by sophisticated Human Error Probabilities (HEPs) derived from Bayesian statistical networks and empirical operational data. Commercial utilities and regulatory bodies continuously harvest performance data directly from full-scope, high-fidelity replica simulators. By subjecting hundreds of licensed operational crews to standardized, degraded, beyond-design-basis accident scenarios, researchers capture massive empirical datasets quantifying diagnostic response times, cognitive transition latencies, and error-forcing contextual vulnerabilities, feeding these observations back into dynamic PRA models to ensure technical risk assessments reflect the true, socio-technical reality of plant operations.

8. Organizational Safety Culture and High Reliability Organizing

8.1 The Institute of Nuclear Power Operations (INPO)

The devastating institutional critiques leveled by the Kemeny and Rogovin inquiries delivered a stark ultimatum to the commercial nuclear energy sector: the industry had to radically reorganize its collective institutional apparatus, or face complete regulatory and economic extinction. In direct response to the Kemeny Commission’s finding that the commercial industry suffered from isolated, highly fragmented management structures and an institutional culture of operational complacency, the US nuclear utility executives took an unprecedented, historical step: they established the Institute of Nuclear Power Operations (INPO) in December 1979.

INPO represented a radical experiment in aggressive, industry-wide self-regulation. Up until 1979, individual nuclear utilities operated in profound isolation, treating operational metrics, transient records, and equipment maintenance histories as proprietary corporate information. INPO demolished this operational balkanization. It established an absolute, non-negotiable operational standard across all commercial nuclear sites in the United States, backed by an intrusive, mandatory peer-review framework. Independent teams of seasoned nuclear operations professionals were deployed continuously to conduct multi-week, exhaustive audits of operational standards, control room decorum, management integrity, and human performance practices.

Central to INPO’s existential mission was the absolute eradication of institutional amnesia through the aggressive centralization and distribution of Operating Experience (OE). The industry recognized that the disaster at TMI-2 had essentially occurred eighteen months prior at Davis-Besse, but the critical information had been allowed to rot inside filing cabinets due to a lack of an institutional transmission mechanism. INPO established the Significant Event Evaluation and Information Network (SEE-IN), mandating that every single anomaly, human error, scram, and equipment failure occurring at any commercial reactor in the nation be formally analyzed, categorized, and universally distributed across the global nuclear fleet within days, mandating procedural and structural remediation to ensure a precursor event anywhere was immediately learned everywhere.

8.2 Charles Perrow’s Normal Accidents Theory (NAT)

While the commercial industry worked frantically to construct defensive organizational buffers through INPO, the disaster at Three Mile Island catalyzed one of the most profound, pessimistic, and intellectually disruptive sociological works of the late twentieth century: Charles Perrow’s seminal 1984 treatise, Normal Accidents: Living with High-Risk Technologies. Perrow, a distinguished organizational sociologist who served as an expert analyst for the President’s Commission, utilized the TMI-2 transcripts as the foundational, empirical archetype for his theoretical framework.

Perrow argued that catastrophic accidents are not anomalous, aberrant events caused by defective hardware or rogue, incompetent operators. Rather, in certain classes of advanced, high-hazard technological systems, catastrophic failure is an inherent, structural, and mathematically inevitable systemic output—a “normal” accident. Perrow established that systemic risk is determined by the intersection of two fundamental architectural dimensions:

  • Interactive Complexity: The degree to which components, subsystems, and operational pathways can interact in unfamiliar, unmodeled, unexpected, and invisible sequences. In interactively complex systems, an isolated failure in a mundane secondary system (e.g., polisher demineralizer air lines) can jump physical barriers, triggering unpredictable non-linear failures across primary systems, instrumentation circuits, and operator cognitive models.
  • Tight Coupling: The degree to which operational processes are inextricably linked in absolute, real-time temporal sequences with minimal physical slack, zero buffer capacity, and invariant operational sequences. In tightly coupled systems, physical transients propagate at sonic velocities; there is zero temporal buffer for operators to retreat, analyze, reflect, and deliberate. Chemical reactions, pressures, and boil-offs occur catastrophically fast.

Nuclear power plants, Perrow proved, are the absolute pinnacle of high interactive complexity and extreme tight coupling. Furthermore, Perrow articulated the profound Paradox of Redundancy. Traditional engineering responds to safety failures by layering on more safety systems, more automatic interlocks, more redundant piping, and more procedural rules. Perrow demonstrated that this engineering paradigm directly accelerates catastrophe: every added layer of safety redundancy exponentially increases the interactive complexity of the installation, multiplying the hidden pathways for catastrophic common-mode failures and creating an interface environment that is overwhelmingly opaque and cognitively unmanageable for human beings.

8.3 High Reliability Organization (HRO) Principles in Nuclear Operations

In direct intellectual opposition to Charles Perrow’s deterministic pessimism, a group of prominent social scientists from the University of California, Berkeley—including Todd La Porte, Gene Rochlin, and Karlene Roberts—along with organizational scholars Karl Weick and Kathleen Sutcliffe, pioneered the theoretical doctrine of High Reliability Organizations (HROs). The HRO scholars studied complex, high-hazard systems that operated for sustained decades with astonishing, near-zero catastrophe rates—such as naval aircraft carriers, air traffic control centers, and top-tier nuclear stations—seeking to identify the cultural and behavioral traits that allow organizations to effectively triumph over Perrow’s Normal Accident trap.

The foundational tenets of High Reliability Organizing were forged directly as an antidote to the organizational pathologies unmasked at Three Mile Island. Weick and Sutcliffe codified the five essential mindful infrastructure principles that govern authentic HROs:

  1. Preoccupation with Failure: An unrelenting, proactive organizational paranoia that treats every minor anomaly, unexpected meter flicker, or maintenance deviation not as an acceptable, benign operational quirk, but as a symptom of a potentially catastrophic latent systemic vulnerability.
  2. Reluctance to Simplify: An aggressive refusal to accept simple, clean, comforting diagnostic interpretations of complex, messy, and ambiguous operational phenomena. HROs recognize that complex technologies demand rich, nuanced, and multifaceted cognitive engagement.
  3. Sensitivity to Operations: Continuous, deep situational awareness by senior leadership regarding the raw, front-line, physical reality of the plant floor, systematically tearing down the bureaucratic abstractions that separate executive suites from the technical realities of operators.
  4. Commitment to Resilience: The understanding that unexpected, novel perturbations are mathematically inevitable; the organization trains relentlessly not just to execute static procedures, but to actively absorb shocks, improvise, and successfully bounce back from degraded states.
  5. Deference to Expertise: The radical, situational flattening of organizational hierarchies. During a routine, stable day, decision-making adheres to traditional corporate chains of command. However, the instant an operational transient or dynamic crisis strikes, authority rigidly defers downstream to the individuals possessing the highest functional, physical expertise regarding the specific anomaly—regardless of their rank, seniority, or bureaucratic standing.

9. Simulator Engineering and the Overhaul of Nuclear Operator Training

9.1 Full-Scope Replica Simulators and Regulatory Mandates

Before March 1979, nuclear control room operator training in the United States was shocking in its pedagogical superficiality. Operational crews were trained predominantly on generic, basic-principles analog mockups that bore minimal physical, spatial, or operational resemblance to the actual commercial facilities they would be licensed to command. Simulators were programmed with simplistic, idealized mathematical equations that could only replicate clean, linear, design-basis single-failure transients. Crucially, none of the training simulators in existence in the 1970s were physically or computationally capable of modeling the complex, non-linear thermal-hydraulic phenomena of two-phase steam-water fluid mechanics, core uncovery, bulk boiling, or non-condensable gas generation.

The regulatory post-mortems of TMI-2 obliterated this superficial training ecosystem. The NRC codified sweeping, uncompromising federal mandates—most notably under Title 10 of the Code of Federal Regulations, Part 55 (10 CFR 55). The revised regulations legally mandated that every commercial operating nuclear generating station in the United States construct and maintain an exact, plant-referenced, full-scope replica simulator. The regulatory standard was absolute: the simulator had to replicate the spatial layout, panel curvature, meter styles, switch feel, acoustic responses, annunciator tones, and lighting conditions of the plant’s specific control room with microscopic, one-to-one fidelity.

This regulatory mandate ignited a massive technological revolution in real-time computational thermal-hydraulic physics. Commercial utilities and simulation vendors invested billions in supercomputing architectures capable of running highly advanced, real-time two-phase fluid dynamic mathematical codes, derived directly from state-of-the-art national laboratory codes such as RELAP (Reactor Excursion and Leak Analysis Program) and TRAC. For the first time in history, licensed nuclear operators were subjected to training environments where the complex physics of small-break LOCAs, steam bubble void formations, and saturation-margin losses were calculated dynamically and rendered with absolute mathematical and physical fidelity in real time.

9.2 Crew Resource Management (CRM) Adaptation for Nuclear Teams

Simultaneously, the nuclear industry recognized that technical simulator fidelity was functionally meaningless if the pedagogical focus remained exclusively fixated on individual, isolated technical competence. Following the lead of commercial and military aviation—which had begun engineering Crew Resource Management (CRM) in the wake of catastrophic communication-breakdown disasters like the 1977 Tenerife runway collision—the nuclear sector aggressively imported and transformed CRM principles into the operational fabric of control room watch teams.

Prior to TMI-2, the social architecture of a nuclear control room was defined by an authoritarian, militaristic, and deeply hierarchical culture. Senior reactor operators and shift supervisors ruled panels with unquestioned authority, and junior control room operators or auxiliary personnel were actively discouraged from questioning diagnostic assumptions or challenging procedural interpretations. At TMI-2, several junior personnel had observed isolated parameters that hinted at an open relief valve or an uncovered core, but their observations were systematically muted or brushed aside by senior operational hierarchy.

The nuclear adaptation of CRM established structured, standardized communication and social operational protocols designed to eradicate conversational ambiguity and flatten destructive social gradients:

  • Closed-Loop Communications: Mandating the universal, three-way repeat-back protocol. When an operational command is issued, the receiver must repeat the exact instruction verbatim, and the sender must formally verify that the communication was accurately decoded before physical switch actuation occurs.
  • Assertiveness and Challenge Mandates: Junior operators are rigorously trained, evaluated, and legally empowered to voice concerns, challenge anomalous plant indications, and formally demand diagnostic timeouts if an operational sequence deviates from understood trajectories.
  • Command Team Shared Situational Awareness: Establishing formal, structured “control board updates”—periodic, mandatory pauses during dynamic accidents where the shift supervisor calls a halt to physical actions, steps back from the panels, verbally synthesizes the plant’s macro-thermodynamic state, solicits dissenting hypotheses from all crew members, and confirms the active Critical Safety Function strategy.

9.3 Scenario-Based Stress Inoculation and Precursor Training

The philosophy of simulator pedagogical instruction underwent an equally radical evolution: transitioning from predictable, idealized “scripted” training to dynamic, scenario-based stress inoculation. Historically, operator evaluations were heavily telegraphic; candidates were subjected to clean, isolated, single-failure events (e.g., “Turbine Trip at 100% Power”), allowing the crew to comfortably anticipate procedural pathways and execute rehearsed mechanical behaviors.

Post-TMI training doctrines abandoned this clean, artificial pedagogical construct in favor of complex, “dirty,” beyond-design-basis accident simulations. Training scenarios were deliberately engineered by simulator instructors to include cascading, multi-system failures, severe electrical bus losses, simultaneous secondary and primary boundary breaches, and deceptive instrument failure modes. Simulators were programmed to replicate corrupted sensor readings, stuck valves, and disconnected command-feedback indicators—forcing operators to actively cross-correlate disparate, secondary physical parameters to verify the true state of the plant.

Crucially, instructional debriefing methodologies were completely reconstructed around cognitive and human factors metrics. The historical paradigm of punitive grading—focused exclusively on whether an operator pressed a specific button within a rigid time envelope—was replaced by comprehensive, video-recorded cognitive debriefs. Simulator instructors, trained in applied human factors, meticulously broke down the watch team’s communication vectors, diagnostic branch points, information-gathering scan paths, confirmation bias traps, and command-team dynamics. Training shifted from the mechanical memorization of static switch actions to the active, resilient conditioning of human cognitive processing under acute psychological and environmental stress.

10. Cross-Disciplinary Diffusion: Aviation, Process Safety, and Medicine

10.1 Aviation Safety and Human-Centered Automation

The rich theoretical and forensic body of knowledge generated in the wake of Three Mile Island did not remain confined within the barbed-wire perimeters of the commercial nuclear industry. Instead, it catalyzed an intellectual diaspora, diffusing rapidly across other ultra-critical, high-consequence technological domains that were grappling with identical challenges of human cognition, automation, and systemic complexity. The first domain to actively ingest and cross-pollinate the post-TMI paradigm was commercial aviation.

As commercial transport aircraft rapidly transitioned throughout the 1980s and 1990s into highly computerized, fly-by-wire “glass cockpit” architectures—typified by the introduction of the Airbus A320 and the Boeing 777—aviation engineers encountered precisely the cognitive interface traps unmasked at Londonderry Township. The legendary aviation human factors research spearheaded by Earl Wiener, Charles Billings, and Nadine Sarter regarding “Automation Surprise” and “Mode Awareness” drew direct intellectual sustenance from the TMI-2 PORV indicator disaster. Sarter and Woods’ famous formulation of the bewildered operator asking: “What is the system doing now? Why is it doing that? What will it do next?” was directly descriptive of the TMI-2 operators staring at the extinguished solenoid light while the core boiled dry.

The post-TMI realization that interfaces must display the actual physical state of the underlying machinery rather than the automated system’s command intent transformed flight deck displays. Flight Management Systems (FMS), primary flight displays, and engine-indicating and crew-alerting systems (EICAS) were structurally redesigned through the lens of human-centered automation. Furthermore, aviation safety adapted the nuclear sector’s comprehensive continuous parameter tracking frameworks, cross-fertilizing Flight Data Monitoring (FDM) and Flight Operational Quality Assurance (FOQA) programs to continuously scan routine flight data for the subtle, latent operational precursors of human-system divergence.

10.2 Chemical Process Safety and Petrochemical Safety Life Cycles

The global chemical and petrochemical processing industries—managing massive inventories of toxic, flammable, and explosive materials—experienced a structural cognitive awakening driven heavily by the operational lessons of Three Mile Island, an awakening further accelerated by their own subsequent industrial catastrophes at Bhopal (1984) and Piper Alpha (1988). The chemical process engineering community realized that their traditional Hazard and Operability (HAZOP) studies were overwhelmingly fixated on static mechanical failures (e.g., pipe erosion, flange leaks, pump motor burnouts) while completely failing to analyze human cognitive vulnerabilities during dynamic plant upsets.

The lessons of TMI-2 directly penetrated international process safety engineering standards, most notably within the codification of the ISA-84 / IEC 61511 international standards governing functional safety and the design of Safety Instrumented Systems (SIS). The petrochemical sector adopted the fundamental nuclear post-TMI mandate: human operational bypasses of automated emergency safety systems were permanently engineered out of the physical infrastructure, or strictly subjected to mathematical Safety Integrity Level (SIL) quantitative performance verification.

Perhaps the most pervasive, direct descendant of TMI-2 in the process sectors was the creation of the international alarm management standard: ANSI/ISA-18.2 (Management of Alarm Systems for the Process Industries). The horrific “annunciator avalanche” that blinded the TMI-2 operators was recognized as a systemic pathogen endemic to chemical refineries and offshore drilling platforms. ISA-18.2 directly codified human engineering limits on alarm metrics, legally establishing that continuous alarm rates must not exceed one alarm per ten minutes during normal operations, and strictly mandating automated alarm rationalization, state-based alarm suppression, and dynamic prioritization matrices to ensure that operators are never again subjected to sensory saturation during high-stakes operational transients.

10.3 Clinical Medicine and Patient Safety Movements

Two decades after Three Mile Island, the healthcare establishment experienced its own historic, devastating epistemological crisis with the publication of the Institute of Medicine’s (IOM) landmark 1999 report, To Err Is Human: Building a Safer Health System. The IOM report revealed that between 44,000 and 98,000 hospitalized patients died annually in the United States alone as a direct consequence of preventable medical errors—dwarfing the casualty rates of commercial aviation and nuclear power combined.

In seeking an intellectual framework to comprehend and rectify this systemic healthcare crisis, the patient safety movement bypassed traditional medical paradigms and directly imported the socio-technical, human error models forged in the post-TMI crucible. Visionary medical scholars, such as anesthesiologist David Gaba and surgeon Lucian Leape, explicitly credited the nuclear and aviation post-accident inquiries for providing the conceptual keys to dismantle medicine’s toxic “blame and train” culture. For over a century, medicine had reflexively pathologized individual doctors and nurses for malpractice and negligence whenever a clinical disaster occurred—a pure manifestation of the discredited “bad apple” doctrine.

Clinical medicine underwent a massive, accelerated transformation directly mirroring the post-TMI nuclear revolution:

  • Crisis Resource Management (ACRM): High-fidelity simulation centers were constructed across the globe to train multidisciplinary clinical teams in the operating room and intensive care units, embedding closed-loop communication, flat social hierarchies, and collective situational awareness directly into medical licensing.
  • Medical Device Human Factors Engineering: Complex, life-critical clinical devices—such as computerized intravenous infusion pumps, hemodialysis consoles, and mechanical ventilators—had historically been notorious for atrocious ergonomic designs that induced deadly dosing errors. The Food and Drug Administration (FDA) implemented sweeping regulations directly requiring Human Factors Engineering Program Reviews modeled on NUREG-0711 prior to medical device certification.
  • Systemic Root Cause Analysis: Hospital sentinel event investigations were formally restructured around James Reason’s Swiss Cheese model and Rasmussen’s cognitive framework, treating clinical errors as the downstream consequence of latent systemic pathogens: fatigue, shift handover breakdown, poor physical ergonomics, and flawed institutional management.

11. Regulatory Transformation and Institutionalization of Human Factors

11.1 NUREG-0700 and Human Factors Engineering Guidelines

Recognizing that control room ergonomics could no longer be relegated to the subjective aesthetic preferences of electrical contractors or commercial utilities, the Nuclear Regulatory Commission transformed human factors research into binding, codified federal engineering standards. The monumental foundational text of this regulatory institutionalization was NUREG-0700: Human-System Interface Design Review Guidelines, initially published in 1981 and continuously refined across subsequent decades.

NUREG-0700 established an exhaustive, highly prescriptive engineering framework governing every physical, visual, auditory, and spatial attribute of the nuclear control room environment. It mandated that every operating commercial nuclear facility in the United States conduct an immediate, comprehensive Detailed Control Room Design Review (DCRDR). Utilities were legally compelled to map every single component, switch, dial, tile, and panel across their operating floors against rigid human engineering criteria, formally identifying every single Human Engineering Discrepancy (HED).

The standard codified granular, mathematically defined engineering limits:

  • Visual Ergonomics: Defining exact character-height-to-viewing-distance ratios, font typography, non-reflective glass coatings, and color-coding conventions (strictly standardizing the meaning of red, green, and amber across all systems).
  • Anthropometric Workstations: Mandating physical panel slopes, reaching radii, sightline angles, and console heights to accommodate the 5th to the 95th anthropometric percentiles of the operational workforce.
  • Annunciator Architectures: Mandating strict spatial grouping of alarm tiles directly above the specific system control panels they monitor, backed by required distinct visual states (unacknowledged flashing, acknowledged steady, clear ring-back) and standardized acoustic frequencies to eliminate auditory cacophony.
  • Labeling and Demarcation: Eradicating ambiguous vendor jargon and introducing formalized system mimic lines—bold, color-coded physical piping paths embedded directly onto the face of the vertical control boards—allowing operators to visually and physically trace the flow of fluid and power across components without cognitive friction.

11.2 NUREG-0711: The Human Factors Engineering Program Review Model

As nuclear engineering transitioned into the late twentieth and early twenty-first centuries, the regulatory philosophy matured from the retrospective patching of existing control rooms to the comprehensive, proactive integration of human factors across the entire life cycle of nuclear facility design and modification. This modern life-cycle methodology was definitively codified in NUREG-0711: Human Factors Engineering Program Review Model.

NUREG-0711 establishes that human factors is not a cosmetic, post-hoc operational consideration, but a core, foundational systems engineering discipline that must govern a technological facility from conceptual genesis through decommissioning. The standard mandates an uncompromising, twelve-element programmatic review process that any nuclear design change or new reactor build must systematically satisfy:

  1. HFE Program Management
  2. Operating Experience Review (OER)
  3. Functional Requirements Analysis and Function Allocation
  4. Task Analysis
  5. Staffing and Qualifications
  6. Human Reliability Assessment (HRA)
  7. Human-System Interface (HSI) Design
  8. Procedure Development
  9. Training Program Development
  10. Human Factors Verification and Validation (V&V)
  11. Design Implementation
  12. Human Performance Monitoring

The crown jewel of the NUREG-0711 framework is Element 10: Integrated System Validation (ISV). Under ISV mandates, an engineering modification or new digital control room architecture cannot receive regulatory certification through analytical calculations alone. The entire completed socio-technical system must be evaluated through rigorous, empirical, human-in-the-loop testing on full-scope replica simulators. Multiple operating crews must execute complete batteries of highly degraded, beyond-design-basis scenarios under rigorous scientific observation. The system is evaluated against strict, quantitative pass/fail criteria measuring human task completion times, cognitive workload indices (utilizing tools such as NASA-TLX), situational awareness scores, and biometric error rates—scientifically proving that the technical system inherently supports human cognitive performance before a single curie of radioactivity is introduced.

11.3 The Evolution of Operator Licensing and Qualification Frameworks

The institutional revolution initiated by TMI-2 permanently remade the human pipeline through which commercial nuclear operators are recruited, educated, evaluated, and licensed by federal authorities. Prior to 1979, the NRC licensing examination was overwhelmingly academic, pencil-and-paper, and theoretical. An applicant could successfully achieve a Senior Reactor Operator (SRO) license by demonstrating an advanced mathematical grasp of neutron physics, thermodynamic thermodynamics equations, and electrical schematics, even if their behavioral, communicative, and situational command on an operational control board was profoundly deficient.

Post-TMI, the regulatory apparatus transformed operator licensing into an intensely rigorous, multi-tiered, simulator-driven behavioral assessment. Under the modernized mandates of 10 CFR 55, no candidate can obtain or maintain a reactor operator license without passing comprehensive, dynamic operational examinations conducted on certified plant-referenced full-scope simulators. Licensing examiners evaluate candidates not merely on technical accuracy, but explicitly on CRM metrics: closed-loop communication adherence, assertive error interception, team situational awareness maintenance, and the structured execution of symptom-oriented procedures under extreme time-compressed scenarios.

Furthermore, the regulatory framework instituted the mandatory position of the Shift Technical Advisor (STA)—a dedicated engineering professional possessing advanced degrees in nuclear science, stationed in the control room to provide independent, high-level thermodynamic diagnostic counsel directly to the shift supervisor during abnormal plant transients, completely insulated from mundane operational switch-throwing tasks. The federal regulatory apparatus also introduced strict, legally binding operational work-hour limits and fatigue-management protocols under 10 CFR 26 (Fitness for Duty Programs), scientifically acknowledging that circadian disruptions, chronic sleep deprivation, and operational exhaustion are catastrophic biological pathogens that degrade human cognitive processing and directly induce technological catastrophe.

12. Contemporary Epistemological Legacies and Future Frontiers in Safety Science

12.1 The Transition from Safety-I to Safety-II in Critical Infrastructure

Four decades of continuous scholarship following the Three Mile Island incident have brought safety science to an advanced, highly sophisticated philosophical crossroads. While the immediate post-TMI era successfully transformed ergonomics, procedures, and training, the modern safety theoretical community—led by thinkers such as Erik Hollnagel—has mounted a profound intellectual critique of the traditional, post-TMI error taxonomy itself, characterizing it as the era of “Safety-I.”

Safety-I is defined by an exclusive, retrospective obsession with what goes wrong. It views safety as a condition where as few things as possible fail. In this framing, the system is conceptualized as inherently safe, and human variability is viewed predominantly as a threat to be suppressed, constrained, and proceduralized out of existence. Hollnagel argues that Safety-I has reached its absolute point of diminishing returns. Modern ultra-safe systems, such as commercial nuclear power and aviation, have driven catastrophic hardware and procedural failure rates to unprecedented historical lows; continuing to obsess solely over the vanishingly rare instances of failure provides almost zero meaningful insight into how these complex, socio-technical operations actually function on a daily basis.

This realization has ignited the historic paradigm shift toward “Safety-II.” Safety-II inverts the epistemological premise: safety is redefined not as the absence of negative events, but as the active presence of operational resilience—the continuous ability of a socio-technical system to succeed under varying, unpredictable, and degraded conditions. Safety-II focuses on why things go right. In complex, modern high-hazard environments, human variability is no longer conceptualized as a destructive, errant deviation from static algorithmic code; rather, human performance variability is recognized as the vital, indispensable, adaptive resource that allows brittle, complex systems to function safely every single day in the face of incomplete procedures, shifting goals, and ambiguous data.

To operationalize this radical philosophy, safety science is increasingly replacing linear, sequential accident models (even advanced event-trees) with non-linear, systemic modeling tools such as the Functional Resonance Analysis Method (FRAM). FRAM abandons the concept of root cause and component failure altogether. Instead, it models the complex socio-technical enterprise as an interconnected network of dynamic, everyday operational functions, mathematically and visually demonstrating how the natural, necessary, and normal variability of individual human and technical functions can resonate together unpredictably, generating sudden, emergent systemic failures or, conversely, extraordinary operational triumphs.

12.2 Digital Instrumentation and Control (I&C) and Modern Complexity

As the commercial nuclear fleet enters the twenty-first century, it is undergoing an unprecedented, massive technological transformation: the wholesale decommissioning of legacy, analog, hardwired control boards and the sweeping installation of fully modernized, computerized, software-driven Digital Instrumentation and Control (Digital I&C) systems. This digital transition, while radically increasing signal processing power and hardware reliability, has inadvertently engineered an entirely new generation of profound ergonomic and cognitive vulnerabilities that directly echo the fundamental challenges of TMI-2.

Chief among these modern cognitive phenomena is the dangerous “Keyhole Effect.” In an archaic analog control room—such as the legacy TMI-2 panels—the human operator was immersed within a vast, continuous, spatially fixed physical panorama. Thousands of switches, gauges, and spatial mimic lines were simultaneously visible across dozens of feet of panels; an operator could casually glance across the room and instantaneously capture the macro-thermodynamic state of the entire facility through peripheral vision and spatial memory. In a modern digital control room, this vast physical landscape is collapsed into a small cluster of computerized visual display units (VDUs) and flat touchscreens.

The operator is forced to perceive a massively complex, multidimensional physical reactor through a narrow, flat, two-dimensional “keyhole.” Vital parameters are buried deep within nested, multi-layered menus, software tabs, and paging hierarchies. Post-upgrade human factors studies have demonstrated that digital interfaces frequently induce profound spatial disorientation: operators become lost in computerized menu trees, losing macro-situational awareness while drilling down to inspect a localized component. When a dynamic transient occurs, the operator must execute multiple physical mouse clicks or touchscreen navigations simply to correlate interrelated parameters, introducing severe, dangerous cognitive latencies that were completely absent in hardwired, spatially dedicated environments.

Furthermore, the modern nuclear paradigm must confront the emerging crisis of cyber-human vulnerability. In Generation III+ and advanced small modular reactors (SMRs), control systems are complex, cyber-physical architectures. Human operators are no longer merely monitoring physical mechanical failures like unseated valves; they must now possess the cognitive capability to diagnose and mitigate subtle, stealthy cyber-physical anomalies—where sophisticated, malicious cyber intrusions deliberately spoof sensor telemetry, projecting calm, nominal conditions on flat-panel VDUs while maliciously driving the physical reactor machinery toward severe thermal destruction. The core challenge of TMI—the fatal divergence between what the display tells the human and what the physical plant is actually doing—has been weaponized in the digital age.

12.3 Autonomous Systems, Artificial Intelligence, and the Supervised Operator

The ultimate contemporary frontier in nuclear safety science resides at the convergence of human cognitive systems engineering and advanced Artificial Intelligence (AI). With the conceptual development and deployment of Generation IV advanced reactor architectures—such as High-Temperature Gas-Cooled Reactors (HTGRs), Molten Salt Reactors (MSRs), and highly compact Small Modular Reactors (SMRs)—the global energy apparatus is heavily pivoting toward hyper-autonomous operation, edge automation, and centralized multi-unit autonomous management.

In these cutting-edge technological paradigms, the human being is definitively removed from the traditional role of an active, manual, hands-on operator. The human is elevated to the detached, highly abstract role of an “autonomous system supervisor.” Machine-learning algorithms and complex neural networks execute real-time reactor diagnostics, autonomously throttle control rods, dynamically modulate coolant loops, and theoretically balance complex thermodynamic envelopes without any required human intervention.

Yet, this modern technocratic dream resurrects the fundamental ghosts of Three Mile Island in an exponentially more terrifying form:

  • Algorithmic Over-Reliance Versus Skepticism: When automated, AI-driven diagnostic systems operate with near-flawless reliability across months of nominal operations, human supervisors inevitably succumb to profound automation complacency. The biological capacity for vigilant, critical skepticism atrophies, leaving the human profoundly vulnerable when the autonomous system inevitably encounters an unmodeled edge-case failure outside its machine-learning training data.
  • The Explainable AI (XAI) Challenge: When an advanced, deep-learning diagnostic network detects an anomalous thermodynamic trend and initiates a drastic, novel operational transient, it presents the ultimate “Gulf of Evaluation.” If the AI functions as a mathematically opaque “black box”—incapable of visually and conceptually rendering its underlying mathematical rationale, hypotheses, and confidence intervals to the human supervisor in real time—the human operator is thrust back into the exact cognitive nightmare of March 28, 1979: observing a machine executing baffling, dynamic interventions with zero comprehensible mental models to evaluate whether the automated system is rescuing the reactor or driving it into a catastrophic core melt.

The timeless, profound lesson forged in the molten core of Three Mile Island Unit 2 remains mathematically, conceptually, and operationally invariant across all technological epochs: no matter how sophisticated the hardware, no matter how advanced the automation, and no matter how complex the algorithmic intelligence, safety in high-hazard socio-technical systems can never be guaranteed by treating the human element as an afterthought. The human operator is the ultimate, indispensable locus of comprehension, resilience, and ethical responsibility; and any engineering architecture that fails to respect the biological and cognitive realities of human performance is an architecture that harbors within its very design the latent, mathematical inevitability of its own destruction.

Conclusion

The catastrophe at Three Mile Island was a watershed moment in human history, marking the precise historical juncture where industrial civilization was violently disabused of its deterministic, component-level engineering arrogance. The protracted core meltdown of Unit 2 demonstrated with terrifying clarity that technological safety cannot be achieved simply by accumulating redundant stainless-steel pipes, multiplying automated safety injection loops, or demanding mechanical obedience to rigid, unyielding procedures. When the dynamic, non-linear realities of physical thermodynamics clash with ambiguous human-machine interfaces, sensory-saturating control board environments, and deeply flawed organizational cultures, catastrophe is the inevitable systemic output.

The true legacy of Three Mile Island resides in the profound, interdisciplinary intellectual diaspora it ignited. The disaster definitively destroyed the naive, punitive “operator error” paradigm, birthing in its place the modern sciences of Human Factors Engineering, Cognitive Systems Engineering, Second-Generation Human Reliability Assessment, and High Reliability Organizing. It forced science to recognize that safety is not a static property engineered into physical hardware, but an emergent, dynamic property continuously co-created across the delicate, complex boundary of the Joint Cognitive System.

As modern technological society stands on the threshold of an unprecedented digital and autonomous revolution—deploying advanced artificial intelligence, cyber-physical control architectures, and hyper-autonomous machines across nuclear, chemical, aerospace, and medical critical infrastructures—the cognitive lessons of Three Mile Island remain more urgently vital than ever. The modern engineer who designs an opaque digital interface, the corporate executive who cultivates institutional complacency, or the systems architect who treats the human operator as a passive, expendable appendage to an algorithmic machine is simply recreating, in modern code, the exact same socio-technical vulnerabilities that boiled the water out of the Susquehanna River reactor forty-five years ago. The ongoing study of Three Mile Island is not an academic post-mortem of an obsolete twentieth-century mechanical system; it is the enduring, foundational manual for ensuring human survival alongside the complex technological titans of the twenty-first century.

References

Rate This Content

0.0 / 5 0 votes

Cite This Article

memjavad (2026, September 17). The Three-Mile Island Human Error Analysis – A field of study following the event. PSYCHOLOGICAL DATABASE. https://en.arabpsychology.com/experiments/three-mile-island-human-error-analysis-field-of-study/
memjavad. “The Three-Mile Island Human Error Analysis – A field of study following the event.” PSYCHOLOGICAL DATABASE, 17 September 2026, https://en.arabpsychology.com/experiments/three-mile-island-human-error-analysis-field-of-study/.
memjavad. “The Three-Mile Island Human Error Analysis – A field of study following the event.” PSYCHOLOGICAL DATABASE. September 17, 2026. https://en.arabpsychology.com/experiments/three-mile-island-human-error-analysis-field-of-study/.