

翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。

# FHIR 対応 HealthLake データストアでの SMART の作成
<a name="reference-smart-on-fhir-create-data-store"></a>

HealthLake で SMART on FHIR フレームワークを使用するには、`CreateFHIRDatastore`リクエストで指定された `IdentityProviderConfiguration`パラメータを使用して HealthLake データストアを作成します。`IdentityProviderConfiguration` パラメータで、次の情報を指定します。
+ [AuthorizationStrategy](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html) を に設定します`SMART_ON_FHIR_V1`。
+ [IdpLambdaArn](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html) を AWS Lambda 、認可サーバーでトークンデコードを管理するために作成した の ARN と等しく設定します。
+ 認可サーバーで指定された[メタデータ](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)要素を JSON ブロックとして定義します。これらのメタデータ要素は、 検出ドキュメントで返されます。
+ *オプション*: [FineGrainedAuthorizationEnabled](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html) を有効にします。HealthLake が提供するきめ細かな認可`True`を使用するには、 を指定します。

**注記**  
データストアを作成したら、 を使用して、`AuthorizationStrategy`、、`Metadata`、および `FineGrainedAuthorizationEnabled`値を含む ID `IdpLambdaArn`プロバイダー設定を変更できます`UpdateFHIRDatastore`。ID プロバイダー設定を更新すると、ID プロバイダー設定が完全に置き換えられるため、保持するすべてのフィールドを含めます。省略したフィールドはクリアされます。ID プロバイダーの更新はすぐに有効になり、データストアを `UPDATING`ステータスに移行しません。詳細については、「[HealthLake データストアの更新](managing-data-stores-update.md)」を参照してください。

SMART on FHIR 対応データストアを作成するには、 AWS Command Line Interface (AWS CLI) を使用するか、 AWS サポートされている SDKs のいずれかを使用します。FHIR 対応 HealthLake データストアでの SMART の作成はHealthLakeコンソールではサポートされていません。

## AWS CLI を使用して FHIR 対応 HealthLake データストアに SMART を作成する
<a name="create-smart-ds-request"></a>

次のコード例を使用して、 を使用して FHIR 対応 HealthLake データストアで SMART を作成できます AWS CLI。FHIR 対応 HealthLake データストアで SMART を作成するときは、 [`identity-provider-configuration`](https://docs.aws.amazon.com/healthlake/latest/APIReference/API_IdentityProviderConfiguration.html)パラメータを指定する必要があります。

`identity-provider-configuration` パラメータでは、*オプション*で を `FineGrainedAuthorizationEnabled`に等しく設定することで、きめ細かな認可を有効にできます`True`。きめ細かな認可の詳細については、「」を参照してください[SMART on FHIR 対応 HealthLake データストアでのきめ細かな認可の使用](reference-smart-on-fhir-fine-grained-authorization.md)。以下の例には、改行`\`を示す特殊文字またはエスケープ文字が含まれています。これはわかりやすくするためです。

```
aws healthlake create-fhir-datastore \
  --region us-east-1 \
  --datastore-name "your-data-store-name" \
  --datastore-type-version R4 \
  --preload-data-config PreloadDataType="SYNTHEA" \
  --sse-configuration '{ "KmsEncryptionConfig": { \
    "CmkType": "customer-managed-kms-key1",
    "KmsKeyId": "arn:aws:kms:us-east-1:your-account-id:key/your-key-id" } }' \
  --identity-provider-configuration  \
      '{"AuthorizationStrategy": "SMART_ON_FHIR_V1", \
      "FineGrainedAuthorizationEnabled": boolean-false-by-default, \
      "IdpLambdaArn": "arn:aws:lambda:your-region:your-account-id:function:your-lambda-name", \
      "Metadata": "{\"issuer\":\"https://ehr.example.com\",\"jwks_uri\":\"https://ehr.example.com/.well-known/jwks.json\",\"authorization_endpoint\":\"https://ehr.example.com/auth/authorize\",\"token_endpoint\":\"https://ehr.token.com/auth/token\",\"token_endpoint_auth_methods_supported\":[\"client_secret_basic\",\"foo\"],\"grant_types_supported\":[\"client_credentials\",\"foo\"],\"registration_endpoint\":\"https://ehr.example.com/auth/register\",\"scopes_supported\":[\"openid\",\"profile\",\"launch\"],\"response_types_supported\":[\"code\"],\"management_endpoint\":\"https://ehr.example.com/user/manage\",\"introspection_endpoint\":\"https://ehr.example.com/user/introspect\",\"revocation_endpoint\":\"https://ehr.example.com/user/revoke\",\"code_challenge_methods_supported\":[\"S256\"],\"capabilities\":[\"launch-ehr\",\"sso-openid-connect\",\"client-public\"]}"}'
```

成功すると、次の JSON レスポンスが表示されます。

```
{
  "DatastoreArn": "arn:aws:healthlake:your-region:111122223333:datastore/fhir/your-datastore-id",
  "DatastoreEndpoint": "https://healthlake.{{region}}.amazonaws.com/datastore/{{datastoreId}}/r4/",
  "DatastoreId": "your-data-store-id",
  "DatastoreStatus": "data-store-creation-status"
}
```