View a markdown version of this page

在启用 FHIR HealthLake 的数据存储上创建 SMART - AWS HealthLake

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

在启用 FHIR HealthLake 的数据存储上创建 SMART

要将 SMART on FHIR 框架与一起使用 HealthLake,请使用CreateFHIRDatastore请求中指定的IdentityProviderConfiguration参数创建 HealthLake 数据存储。在IdentityProviderConfiguration参数中指定以下信息:

  • 将AuthorizationStrategy等于设置为SMART_ON_FHIR_V1。

  • 设置IdpLambdaArn等于 AWS Lambda 您创建的 ARN,以便使用授权服务器管理令牌解码。

  • 将授权服务器中指定的元数据元素定义为 JSON 块。这些元数据元素将在探索文档中返回。

  • 可选:启用FineGrainedAuthorizationEnabled。指定使用True提供的 Fine Grained 授权 HealthLake

注意

创建数据存储后,您可以使用更改其身份提供商配置,包括AuthorizationStrategy、IdpLambdaArnMetadata、和FineGrainedAuthorizationEnabled值。UpdateFHIRDatastore更新身份提供商配置会完全取代它,因此请包括您要保留的所有字段;您省略的任何字段都将被清除。身份提供商更新立即生效,不会将数据存储移动到UPDATING状态。有关更多信息,请参阅 更新 HealthLake 数据存储。

您可以使用 AWS Command Line Interface (AWS CLI) 或通过 AWS 支持的 SDK 之一在启用 FHIR 的数据存储上创建 SMART。 HealthLake 控制台不支持在启用 FHIR HealthLake 的数据存储上创建 SMART。

使用 AWS CLI 在启用 FHIR HealthLake 的数据存储上创建 SMART

您可以使用以下代码示例,使用在启用 FHIR HealthLake 的数据存储上创建 SMART。 AWS CLI在启用 FHIR HealthLake 的数据存储上创建 SMART 时,必须指定identity-provider-configuration参数。

在identity-provider-configuration参数中,您可以选择通过设置FineGrainedAuthorizationEnabled等于来启用细粒度授权。True要了解有关细粒度授权的更多信息,请参阅在启用 SMART on FHIR 的数据存储中使用细粒度授权 HealthLake。下面的示例包含一个特殊字符\,用于表示换行符或作为转义字符。这是为了清楚起见。

aws healthlake create-fhir-datastore \ --region us-east-1 \ --datastore-name "your-data-store-name" \ --datastore-type-version R4 \ --preload-data-config PreloadDataType="SYNTHEA" \ --sse-configuration '{ "KmsEncryptionConfig": { \ "CmkType": "customer-managed-kms-key1", "KmsKeyId": "arn:aws:kms:us-east-1:your-account-id:key/your-key-id" } }' \ --identity-provider-configuration \ '{"AuthorizationStrategy": "SMART_ON_FHIR_V1", \ "FineGrainedAuthorizationEnabled": boolean-false-by-default, \ "IdpLambdaArn": "arn:aws:lambda:your-region:your-account-id:function:your-lambda-name", \ "Metadata": "{\"issuer\":\"https://ehr.example.com\",\"jwks_uri\":\"https://ehr.example.com/.well-known/jwks.json\",\"authorization_endpoint\":\"https://ehr.example.com/auth/authorize\",\"token_endpoint\":\"https://ehr.token.com/auth/token\",\"token_endpoint_auth_methods_supported\":[\"client_secret_basic\",\"foo\"],\"grant_types_supported\":[\"client_credentials\",\"foo\"],\"registration_endpoint\":\"https://ehr.example.com/auth/register\",\"scopes_supported\":[\"openid\",\"profile\",\"launch\"],\"response_types_supported\":[\"code\"],\"management_endpoint\":\"https://ehr.example.com/user/manage\",\"introspection_endpoint\":\"https://ehr.example.com/user/introspect\",\"revocation_endpoint\":\"https://ehr.example.com/user/revoke\",\"code_challenge_methods_supported\":[\"S256\"],\"capabilities\":[\"launch-ehr\",\"sso-openid-connect\",\"client-public\"]}"}'

成功后,您将获得以下 JSON 响应:

{ "DatastoreArn": "arn:aws:healthlake:your-region:111122223333:datastore/fhir/your-datastore-id", "DatastoreEndpoint": "https://healthlake.region.amazonaws.com/datastore/datastoreId/r4/", "DatastoreId": "your-data-store-id", "DatastoreStatus": "data-store-creation-status" }