This document provides an introduction to the book "Information Security in Healthcare: Managing Risk". It discusses that privacy should be a critical component of any healthcare institution's strategic vision or operational plan. While privacy is not explicitly defined in the US Constitution, it is viewed as an important part of personal freedom, especially as it relates to personal health information. The introduction defines information privacy as individuals having control over their personal information and reasonable expectations about how it will be used and disclosed. Healthcare institutions must balance an individual's privacy rights with using confidential information for necessary clinical and business tasks. The focus of the book is on protecting privacy for all constituencies within a healthcare organization, including employees, patients, providers and volunteers.