View a markdown version of this page

FHIR 対応 HealthLake データストアでの SMART の作成 - AWS HealthLake

翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。

FHIR 対応 HealthLake データストアでの SMART の作成

HealthLake で SMART on FHIR フレームワークを使用するには、CreateFHIRDatastoreリクエストで指定された IdentityProviderConfigurationパラメータを使用して HealthLake データストアを作成します。IdentityProviderConfiguration パラメータで、次の情報を指定します。

  • AuthorizationStrategy を に設定しますSMART_ON_FHIR_V1。

  • IdpLambdaArn を AWS Lambda 、認可サーバーでトークンデコードを管理するために作成した の ARN と等しく設定します。

  • 認可サーバーで指定されたメタデータ要素を JSON ブロックとして定義します。これらのメタデータ要素は、 検出ドキュメントで返されます。

  • オプション: FineGrainedAuthorizationEnabled を有効にします。HealthLake が提供するきめ細かな認可Trueを使用するには、 を指定します。

注記

データストアを作成したら、 を使用して、AuthorizationStrategy、、Metadata、および FineGrainedAuthorizationEnabled値を含む ID IdpLambdaArnプロバイダー設定を変更できますUpdateFHIRDatastore。ID プロバイダー設定を更新すると、ID プロバイダー設定が完全に置き換えられるため、保持するすべてのフィールドを含めます。省略したフィールドはクリアされます。ID プロバイダーの更新はすぐに有効になり、データストアを UPDATINGステータスに移行しません。詳細については、「HealthLake データストアの更新」を参照してください。

SMART on FHIR 対応データストアを作成するには、 AWS Command Line Interface (AWS CLI) を使用するか、 AWS サポートされている SDKs のいずれかを使用します。FHIR 対応 HealthLake データストアでの SMART の作成はHealthLakeコンソールではサポートされていません。

AWS CLI を使用して FHIR 対応 HealthLake データストアに SMART を作成する

次のコード例を使用して、 を使用して FHIR 対応 HealthLake データストアで SMART を作成できます AWS CLI。FHIR 対応 HealthLake データストアで SMART を作成するときは、 identity-provider-configurationパラメータを指定する必要があります。

identity-provider-configuration パラメータでは、オプションで を FineGrainedAuthorizationEnabledに等しく設定することで、きめ細かな認可を有効にできますTrue。きめ細かな認可の詳細については、「」を参照してくださいSMART on FHIR 対応 HealthLake データストアでのきめ細かな認可の使用。以下の例には、改行\を示す特殊文字またはエスケープ文字が含まれています。これはわかりやすくするためです。

aws healthlake create-fhir-datastore \ --region us-east-1 \ --datastore-name "your-data-store-name" \ --datastore-type-version R4 \ --preload-data-config PreloadDataType="SYNTHEA" \ --sse-configuration '{ "KmsEncryptionConfig": { \ "CmkType": "customer-managed-kms-key1", "KmsKeyId": "arn:aws:kms:us-east-1:your-account-id:key/your-key-id" } }' \ --identity-provider-configuration \ '{"AuthorizationStrategy": "SMART_ON_FHIR_V1", \ "FineGrainedAuthorizationEnabled": boolean-false-by-default, \ "IdpLambdaArn": "arn:aws:lambda:your-region:your-account-id:function:your-lambda-name", \ "Metadata": "{\"issuer\":\"https://ehr.example.com\",\"jwks_uri\":\"https://ehr.example.com/.well-known/jwks.json\",\"authorization_endpoint\":\"https://ehr.example.com/auth/authorize\",\"token_endpoint\":\"https://ehr.token.com/auth/token\",\"token_endpoint_auth_methods_supported\":[\"client_secret_basic\",\"foo\"],\"grant_types_supported\":[\"client_credentials\",\"foo\"],\"registration_endpoint\":\"https://ehr.example.com/auth/register\",\"scopes_supported\":[\"openid\",\"profile\",\"launch\"],\"response_types_supported\":[\"code\"],\"management_endpoint\":\"https://ehr.example.com/user/manage\",\"introspection_endpoint\":\"https://ehr.example.com/user/introspect\",\"revocation_endpoint\":\"https://ehr.example.com/user/revoke\",\"code_challenge_methods_supported\":[\"S256\"],\"capabilities\":[\"launch-ehr\",\"sso-openid-connect\",\"client-public\"]}"}'

成功すると、次の JSON レスポンスが表示されます。

{ "DatastoreArn": "arn:aws:healthlake:your-region:111122223333:datastore/fhir/your-datastore-id", "DatastoreEndpoint": "https://healthlake.region.amazonaws.com/datastore/datastoreId/r4/", "DatastoreId": "your-data-store-id", "DatastoreStatus": "data-store-creation-status" }