Case file
- What happened: In early 1993, hamburgers contaminated with E. coli O157:H7 and served undercooked at Jack in the Box restaurants across the western United States caused one of the deadliest foodborne illness outbreaks in American history.
- Scale: Over 700 illnesses, 171 hospitalisations, and four deaths. Most severe cases were young children.
- Root cause: A cooking process neither validated against a lethal biological hazard nor controlled as a critical parameter. Contaminated raw beef entered restaurants; the grills did not reliably reach the temperature needed to kill the pathogen.
- The bill: Four children dead. Hundreds of families affected. The financial cost ran into hundreds of millions of dollars. The fast-food industry rewrote its food safety controls from the ground up.
The situation
January 1993. Jack in the Box was a major fast-food chain across the western United States. Hamburgers were a core menu item, cooked to time-and-temperature guidelines the company believed were compliant — derived from FDA standards that predated any formal requirement to treat E. coli O157:H7 as an adulterant in ground beef. The pathogen was not unknown. A 1982 outbreak traced to another fast-food chain had already identified it. But the regulatory framework had not caught up with the science. The USDA had not declared E. coli O157:H7 an adulterant. HACCP was not yet industry standard. The prevailing assumption: cook a burger for the prescribed time at the prescribed temperature and it is safe. No one asked what happens if the meat arrives contaminated and the grill is off by a few degrees.How it unfolded
Contaminated beef patties entered the Jack in the Box supply chain and were distributed to restaurants across Washington, Oregon, Idaho, and Nevada. On the grill, patties were cooked according to the company's standard procedures — procedures that fell below the minimum internal temperature Washington state had recently raised to 155°F. The gap between the company's cooking specification and the regulatory requirement was not a rounding error. It was the margin between a safe product and a lethal one. Children ate those hamburgers. E. coli O157:H7 produces a Shiga toxin that attacks the intestinal lining and, in severe cases, causes hemolytic uremic syndrome — kidney failure, brain damage, death. The youngest patients were the most vulnerable. Symptoms appeared days after exposure. By the time epidemiologists traced the outbreak to undercooked burgers, the damage was done.Root-cause anatomy
The technical failure is straightforward. The cooking process was the last line of defence between a lethal pathogen and a child's digestive system, and it was controlled by a time-and-temperature table rather than a validated critical control point. No automated verification. No kill-step confirmation. No requirement to measure internal temperature on every batch. The grill was trusted. The operator was trusted. The patty was not checked. The organisational failure runs deeper. If a PFMEA existed for this process, the severity rating for biological contamination was wrong. A pathogen that kills a child through a single undercooked patty is a Severity 10 — the highest rating on the scale. The detection rating was equally catastrophic. Visual inspection of doneness and standard cook times have a near-zero probability of confirming internal lethal temperature. The occurrence rating, given contaminated beef entering the supply chain undetected, was also understated. Three axes. Three wrong ratings. One dishonest assessment.Where the quality system failed
This was a PFMEA failure from start to finish. The failure mode — contaminated beef reaching a customer because the cooking step was inadequate — should have been identified, rated at maximum severity, and subjected to engineering controls. Instead, the quality system failed on four fronts. If E. coli O157:H7 in a children's product was not rated Severity 10, the risk analysis was structurally broken from line one. The kill step — cooking — was treated as a standard process operation, not a critical control point requiring validated limits and verified monitoring. Incoming raw beef was assumed safe rather than controlled; the supply chain was trusted without verification of biological contamination risk. Audits checked whether procedures existed and were followed, not whether those procedures were capable of controlling a lethal hazard.A work instruction is not a control. It is a hope attached to a procedure.
What would have caught it
A proper PFMEA would have forced the question early: what is the severity of a child consuming a pathogen that produces a lethal toxin? The answer — Severity 10 — triggers a chain of engineering decisions that make undercooking physically impossible. Cooking would have become a validated critical control point: internal temperature verified per batch with automated monitoring and alarm-and-hold logic, not assumed from cook time. Supplier controls would have required certificates of analysis for E. coli O157:H7, lot-level testing, supplier scorecards tied to biological hazard data. A formal HACCP architecture would have identified cooking as the sole kill step, with critical limits, monitoring procedures, corrective actions, and verification records. Process validation — a documented study confirming that the cooking process, as designed and under worst-case conditions, reliably reduces the pathogen to a safe level — would have preceded any product reaching a customer. None of this is exotic. In aerospace manufacturing, every critical process parameter — torque on a fastener, temperature on a cure cycle, dimension on a fracture-critical part — is validated, controlled, and verified. The principle is identical. The difference is that aerospace learned this through certification requirements. The food industry learned it through four dead children.My take
I have spent twenty years building quality systems in automotive and aerospace, and the pattern never changes. When a failure mode is rated Severity 10, you stop delegating it to the operator. You engineer the risk out of the process. In my current role at Airbus, if a process parameter can cause catastrophic failure, it gets an interlock, an automated verification, or a poka-yoke — not a laminated card on the wall. I have applied the same principle under IATF 16949 in automotive, where PFMEA severity drives the entire control plan. I have walked into plants where a critical parameter was controlled by a work instruction taped to a machine. I have reviewed PFMEAs where a genuinely dangerous failure mode was rated Severity 4 because no one wanted to trigger the engineering work that a 10 would demand. Severity 10 triggers paperwork. Severity 4 triggers nothing. Guess which one gets selected when the PFMEA lead is under deadline pressure. The Jack in the Box outbreak cost four children their lives. The CoPQ — cost of poor quality — is measured here not in euros or dollars but in funerals. The brand survived, barely. But the real cost was paid by families who sent their children to a restaurant and never brought them home.What this means on your floor
- Rate severity honestly. If a failure mode can kill a person, it is a 10. The engineering work that follows is the entire point of the rating.
- A work instruction is the weakest control in the hierarchy. For lethal parameters, use engineering controls — interlocks, automated verification, hard failsafes.
- Treat your last line of defence as your most important control. If cooking is the kill step, it gets validated limits and verified monitoring every batch, every time.
- Audit for capability, not just compliance. The question is not "did they follow the procedure." The question is "could this procedure have prevented the failure mode."