Information security and privacy in the healthcare sector is an issue of growing importance. The adoption of digital patient records, increased regulation, provider consolidation, and the increasing need for information between patients, providers, and payers, all point towards the need for better information security. We critically survey the research literature on information security and privacy in healthcare, published in both information systems, non-information systems disciplines including health informatics, public health, law, medicine, and popular trade publications and reports. In this paper, we provide a holistic view of the recent research and suggest new areas of interest to the information systems community.