Product Integrity

When Safety Exists Between Systems

A hospital fire reveals how individually governed systems can create combined safety conditions. What Turku teaches us about Product Integrity, evidence, system interaction and the revised EU Product Liability Directive.

When Safety Exists Between Systems

Product Integrity Spotlight 02 | Hospitals & Healthcare

At 05:41 on 2 September 2011, a fire began above the suspended ceiling of the emergency department at Turku University Hospital in Finland.

The initiating fault was electrical. A connection unit belonging to the nurse call-out system overheated following short circuits in connectors at patient locations. But above that ceiling was another condition that materially altered what happened next.

Investigators concluded that oxygen had already been leaking into the ceiling space before the fire. The pipework was too badly damaged during the event for its pre-fire condition to be established directly, and the available oxygen-consumption information was not sufficiently precise to reveal a leak beforehand.

The elevated oxygen concentration lowered the ignition temperature of materials, increased combustion temperature and accelerated development of the fire. As the fire intensified, heat damaged connections in the oxygen and compressed-air pipework, releasing additional gas.

Smoke then travelled rapidly through openings associated with electrical wiring and other building services, and through lift shafts, staircases, ventilation routes and other penetrations. Fire also spread through an electrical-cable route to the floor above. The building was evacuated except for the intensive care unit.

No patients were reported injured. Three nurses were examined for smoke exposure, and the total damage, including consequential loss, was estimated at approximately EUR 17.5 million.

Describing Turku simply as an electrical fire tells only part of the story. The ignition belonged to one technical system; the conditions that amplified the fire involved another. The developing fire then changed the state of that second system, while the eventual spread involved further parts of the hospital infrastructure.

It is the interaction between those conditions that makes this case particularly important from a Product Integrity perspective.

The fault was electrical. The dangerous condition was broader.

For much of my career I have worked around fire detection and life-safety systems. One lesson becomes difficult to ignore after enough time in that environment: the behaviour of an individual device rarely tells you everything you need to know about the condition of the system around it.

A detector, alarm interface or control unit can perform the function for which it was designed while the significance of an event still depends on ventilation, power, suppression, building configuration, occupancy, cause-and-effect logic and other systems outside the device itself.

Turku provides a particularly clear example. Its technical sequence can be separated into four different conditions:

IGNITION
Nurse-call electrical fault.

AMPLIFICATION
Oxygen enrichment altered the combustion environment.

ESCALATION
Fire damage affected the medical-gas connections and released additional gas.

PROPAGATION
Building-service routes and fire-compartment conditions influenced how the event spread.

This distinction is important because it prevents us from inventing a single failure where the evidence shows an interacting chain.

Hospitals necessarily divide responsibility between specialist disciplines. Electrical installations, medical gases, fire protection, clinical technology, building systems and maintenance all require technical expertise. The governance question is therefore not whether those disciplines should exist. It is whether the organisation can reliably establish the safety condition that emerges when their technical states interact.


The system was being checked

In October 2025, while launching a new programme of hospital technical-safety supervision, Finland's Safety and Chemicals Agency, Tukes, cited the Turku investigation as a historical example.

Tukes referred to the original investigation's findings that necessary pressure testing had not been carried out during refurbishment of the medical-gas pipework and that maintenance plans for the installations were lacking. It also noted that the hospital reported annual gas analyses performed in accordance with the European Pharmacopoeia, but that these principally focused on the quality of the medical gas.

Those are not the same assurance question.

A gas-quality test can be entirely valid for its intended purpose while providing limited information about the integrity of the network carrying the gas. That distinction has a much wider governance implication: an organisation can possess inspection records, test results and maintenance evidence and still lack assurance against the condition that eventually matters.

The question is not simply whether an inspection took place. It is whether the combined assurance regime was capable of revealing the failure condition that needed to be known.

A valid gas-quality test does not necessarily reveal a pipe-network leak. An electrical inspection may assess an electrical installation without establishing the consequences of an ignition source inside an oxygen-enriched environment. A fire-compartmentation inspection can examine a barrier while later modifications elsewhere alter penetrations through it.

Each assurance activity may have a legitimate technical purpose. The exposure can remain in the relationship between them.


Product Integrity does not replace systems safety

There is an important boundary here.

Systems engineering, HAZOP, bowtie analysis, interface-hazard reviews, fire engineering and other established safety disciplines already examine interactions, dependencies and failure pathways. Turku is not evidence that those disciplines are inadequate, and Product Integrity should not claim territory that properly belongs to them.

The Product Integrity question begins somewhere else: what happens to the significance of those specialist conclusions over time and across organisational boundaries?

If a hazard analysis identifies a dependency, does it remain visible after refurbishment? If a medical-gas system is modified, is there a governed reason to revisit assumptions elsewhere? If a fire-safety conclusion depends on a particular building configuration, what happens when maintenance, replacement or reconfiguration changes that condition?

And when several specialist records contain different parts of the operating picture, can the organisation still establish what those records mean together?

Product Integrity does not need to become another engineering discipline. Its role is to test whether technically important conclusions survive the transitions between disciplines, changes and decision-makers strongly enough to support action.

That is different from discovering a hazard in the first place.


The revised Product Liability Directive makes interaction harder to ignore

The Turku fire occurred in 2011. Directive (EU) 2024/2853 did not govern the accident, and the case should not be read retrospectively through a legal regime that did not exist at the time.

Its relevance is forward-looking.

Article 7 of the revised Product Liability Directive provides that defectiveness is assessed in light of all relevant circumstances. Those circumstances include the reasonably foreseeable effect on a product of other products that can be expected to be used together with it, including through interconnection.

That does not transform a hospital into a single product, nor does it make every manufacturer within a technical environment responsible for every other product operating there.

It does, however, weaken the assumption that product safety can always be considered in isolation.

For products whose behaviour depends on surrounding products, infrastructure, software or operating conditions, circumstances relevant to safety may extend beyond the physical boundary of the individual item. Turku demonstrates why that distinction can matter operationally, even though the Directive played no role in the 2011 investigation.


When evidence survives but the condition does not

The investigation encountered another difficulty.

After the fire, the earlier condition of the oxygen pipework could no longer be directly examined because the relevant physical evidence had been severely damaged. Available oxygen-consumption information was not sufficiently precise to establish the earlier leak independently. Investigators therefore had to reconstruct what happened from the development of the fire and the remaining evidence.

This raises another Product Integrity question.

An organisation can retain records and still be unable to reconstruct the technical state that eventually becomes significant.

Under the revised PLD, evidence can become particularly consequential.

Article 9 requires Member States to ensure that, where a claimant has presented facts and evidence sufficient to support the plausibility of a claim, a defendant can be required to disclose relevant evidence at its disposal, subject to necessity and proportionality.

Article 10 retains the claimant's obligation to prove defectiveness, damage and causation. It also establishes targeted presumptions in defined circumstances, including where relevant evidence is not disclosed and where technical or scientific complexity creates excessive difficulty in proving defectiveness or causation, provided the Directive's conditions are met. Those presumptions are rebuttable.

The Turku case tells us nothing about how a future court would apply those provisions. What it does show is how difficult reconstruction can become once the relevant physical state has disappeared.

Years later, the important questions may be:

  • What was the technical condition?
  • What evidence existed at the time?
  • Which assumptions were being relied upon?
  • What changed?
  • Was the significance of that change assessed?
  • Why was the resulting condition considered acceptable?

That is more than document retention. It is evidence architecture.


The combined-condition problem

The Product Integrity proposition I take from Turku is deliberately narrow:

Product integrity is exposed when organisations can govern systems individually but cannot reliably establish the safety condition created by their interaction.

Hospitals make that issue unusually visible.

Medical gases, electrical infrastructure, fire systems, clinical technology, ventilation, power resilience and building systems coexist because patients depend on them. Their normal functions are not independent of one another's consequences.

Oxygen is therapeutically essential. Its presence can also materially alter combustion behaviour.

Ventilation supports the clinical environment while also affecting smoke movement. Electrical and digital systems support clinical and life-safety functions while introducing their own dependencies.

The hospital-specific challenge is therefore not simply complexity. Systems performing legitimate and sometimes safety-critical functions can change the hazard characteristics of other systems around them.

That combined condition has to remain governable as the facility changes.


A four-question combined-condition test

For an executive responsible for a complex safety-relevant environment, I would start with four questions.

01 | SYSTEM INTERACTION

Which systems can materially change another system's risk characteristics?

Think beyond direct physical connections. Power, software, networks, pressure, thermal conditions, ventilation, environmental conditions and common dependencies may all matter.

02 | INTERFACE ASSURANCE

Which assurance activity verifies the relationship rather than only the component?

If every control stops at the technical boundary of the system being inspected, an important assurance gap may remain.

03 | REASSESSMENT TRIGGERS

Which changes require an earlier safety conclusion to be reconsidered?

Refurbishment, replacement, software change, altered maintenance strategies and changed operating conditions should have reassessment triggers where the dependency justifies them.

04 | EVIDENCE RECONSTRUCTION

Could the combined condition be reconstructed after the physical evidence disappeared?

If the answer depends mainly on individual recollection or disconnected records whose significance has to be rediscovered after an event, that is already a governance signal.

These questions do not replace HAZOP, systems safety or specialist technical assurance. They test whether the conclusions those disciplines generate remain connected strongly enough to govern the operating condition throughout its lifecycle.


The interface is not empty space

The important feature of Turku is not that one specialist discipline failed to understand its own technology. The event crossed technical boundaries.

An electrical fault initiated the fire. The combustion environment was influenced by medical oxygen. Fire then changed the condition of the medical-gas system. Propagation involved further parts of the hospital's physical and technical infrastructure.

The Safety Investigation Authority's recommendations consequently extended across structural fire safety, electrical and gas systems, maintenance and repair, inspections, internal communications and automatic fire extinguishing systems.

That breadth reflects the architecture of the event itself.

Complex technical environments increasingly depend on relationships between products, infrastructure, software, maintenance, suppliers and operating conditions. Specialist disciplines may understand their individual parts extremely well.

Product Integrity asks one additional question:

Can the organisation still establish what those parts mean together when it needs to decide?

Turku is a powerful reminder of why that question deserves an answer before an incident provides one.

  • Safety Investigation Authority, Finland — B1/2011Y
    https://www.turvallisuustutkinta.fi/en/investigations/investigation-reports/b1-2011y-fire-led-to-evacuation-from-turku-hospital-on-2-september-2011/
  • Tukes — technical safety of hospitals
    https://tukes.fi/-/tukes-valvoo-sairaaloiden-teknista-turvallisuutta
  • Directive (EU) 2024/2853 — EUR-Lex
    https://eur-lex.europa.eu/eli/dir/2024/2853/oj
This article provides independent analysis and is not legal advice. Regulatory status and dates should be verified against current official sources.