The Office for Civil Rights, which is the arm of the Department of Health and Human Services that enforces HIPAA privacy and security rules, recently announced the settlement of an enforcement action against a small cardiothoracic surgery practice. The practice reportedly posted protected health information (PHI) on an internet-based publically accessible calendar and transmitted PHI