{"_id":"@aws-mdaa/healthlake","_rev":"3-e6853ebf02e8fe61b37a8a31036db4a6","name":"@aws-mdaa/healthlake","dist-tags":{"latest":"1.9.0"},"versions":{"1.8.0":{"name":"@aws-mdaa/healthlake","version":"1.8.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/healthlake@1.8.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"healthlake-cdk":"bin/healthlake.js"},"dist":{"shasum":"6c0f909d802f2f7c587ca96b3d8615fbc422e507","tarball":"https://registry.npmjs.org/@aws-mdaa/healthlake/-/healthlake-1.8.0.tgz","fileCount":16,"integrity":"sha512-i4A1MTLArJd/SiWaZmnzzFrBn3Pn5WQVRlhinVMvJ5YptVNtz8ghK36n5W2VcnVLNRS/A3BOQ9wue1mauOYd0A==","signatures":[{"sig":"MEQCIHssPQA1JWSsRjrR41nrhJhjUofe7SkHLIB1X6fjW2rPAiB85Z8qORWn6wWd3lmbGyrMJlkEoFepRVO3Z2TYI3uYKg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1122417},"main":"lib/index.js","mdaa":{"deployStage":"2"},"_from":"file:/Users/guoneng/.cache/mdaa-publish/mdaa/target/package-build/aws-mdaa-healthlake-1.8.0.tgz","types":"lib/index.d.ts","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../eslint.config.mjs","test":"jest --passWithNoTests --coverage","build":"../../../../scripts/build/build_package.sh HealthLakeConfigContents","watch":"tsc -w","test:package-docs":"../../../../scripts/generate_docs/test_package_docs.sh","test:update-baselines":"UPDATE_BASELINES=true jest --passWithNoTests --testPathPattern='.*\\.diff\\.test\\.ts'"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/.cache/mdaa-publish/mdaa/target/package-build/aws-mdaa-healthlake-1.8.0.tgz","_integrity":"sha512-i4A1MTLArJd/SiWaZmnzzFrBn3Pn5WQVRlhinVMvJ5YptVNtz8ghK36n5W2VcnVLNRS/A3BOQ9wue1mauOYd0A==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.8","description":"MDAA HealthLake FHIR R4 Datastore module","directories":{},"_nodeVersion":"22.23.1","dependencies":{"ajv":"8.18.0","yaml":"1.10.3","cdk-nag":"2.37.55","constructs":"10.6.0","aws-cdk-lib":"2.261.0","@aws-mdaa/app":"1.8.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.8.0","@aws-mdaa/iam-role-helper":"1.8.0","@aws-mdaa/healthlake-l3-construct":"1.8.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.8.0","typescript-json-schema":"0.67.4"},"_npmOperationalInternal":{"tmp":"tmp/healthlake_1.8.0_1788288030724_0.23388778438814906","host":"s3://npm-registry-packages-npm-production"}},"1.8.1":{"name":"@aws-mdaa/healthlake","version":"1.8.1","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/healthlake@1.8.1","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"healthlake-cdk":"bin/healthlake.js"},"dist":{"shasum":"c024da273f78d9c7bd076402905dbdfbe64b13a7","tarball":"https://registry.npmjs.org/@aws-mdaa/healthlake/-/healthlake-1.8.1.tgz","fileCount":16,"integrity":"sha512-rHQPrZ99yMindvr6+5vLblnl//QkcPvb0UWGbbprvO4DQb5Qi713T+ktkQCQEur8rUOrV6JgY92TyIP0ruKuUQ==","signatures":[{"sig":"MEUCIQDJpyJYjkGVJWY8L0H1VyWnSswp3VIEbdvmRbevJ32ewAIgVyrLGPzsKghTqU4tqPJNsU3vo7YbRV7FINS3qvvBhKU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDc7U509hyB5UqgvB9kWYEMSq6V5znxuHU3Npt/Lq96pwIgDkD41Jbn/rmuKDiU56A7Kd6cO6OtV2APpaEQPeVjNy8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1122417},"main":"lib/index.js","mdaa":{"deployStage":"2"},"_from":"file:/Users/guoneng/.cache/mdaa-publish/mdaa/target/package-build/aws-mdaa-healthlake-1.8.1.tgz","types":"lib/index.d.ts","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../eslint.config.mjs","test":"jest --passWithNoTests --coverage","build":"../../../../scripts/build/build_package.sh HealthLakeConfigContents","watch":"tsc -w","test:package-docs":"../../../../scripts/generate_docs/test_package_docs.sh","test:update-baselines":"UPDATE_BASELINES=true jest --passWithNoTests --testPathPattern='.*\\.diff\\.test\\.ts'"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/.cache/mdaa-publish/mdaa/target/package-build/aws-mdaa-healthlake-1.8.1.tgz","_integrity":"sha512-rHQPrZ99yMindvr6+5vLblnl//QkcPvb0UWGbbprvO4DQb5Qi713T+ktkQCQEur8rUOrV6JgY92TyIP0ruKuUQ==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.8","description":"MDAA HealthLake FHIR R4 Datastore module","directories":{},"_nodeVersion":"22.23.1","dependencies":{"ajv":"8.18.0","yaml":"1.10.3","cdk-nag":"2.37.55","constructs":"10.6.0","aws-cdk-lib":"2.261.0","@aws-mdaa/app":"1.8.1","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.8.1","@aws-mdaa/iam-role-helper":"1.8.1","@aws-mdaa/healthlake-l3-construct":"1.8.1"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.8.1","typescript-json-schema":"0.68.0"},"_npmOperationalInternal":{"tmp":"tmp/healthlake_1.8.1_1789417141376_0.09372428661811694","host":"s3://npm-registry-packages-npm-production"}},"1.9.0":{"_id":"@aws-mdaa/healthlake@1.9.0","bin":{"healthlake-cdk":"bin/healthlake.js"},"bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"dist":{"shasum":"e78dd9bb4e57f00189e690a026fe6b4b7cdea2c3","tarball":"https://registry.npmjs.org/@aws-mdaa/healthlake/-/healthlake-1.9.0.tgz","fileCount":16,"integrity":"sha512-HkHfFsC+gs4rLS/boByJvmWHIxfoski3omN2rWebGkw484BK2htl++swHJz+YKEwPbspatljww6k5F5Anp715g==","signatures":[{"sig":"MEQCIDwXmEQLUNYltA3O1N6IGTTIPXh5TInPVfmCRtUnbJkuAiBOiG32PlzJwPNQnZzaMYjJdYgxFDXb4yEEFYSC7fBPHQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAlnGdcp2efcnErQan2EFurqv1dQnL/jLCPwkQg1iL0IAiEAxyzii67Ty+HnMQ1WhOeMG5mtD9Y9dR4kRQ5NQj12HZQ="}],"unpackedSize":1122848},"main":"lib/index.js","mdaa":{"deployStage":"2"},"name":"@aws-mdaa/healthlake","_from":"file:/codebuild/output/src553311566/src/out/mdaa/target/package-build/aws-mdaa-healthlake-1.9.0.tgz","types":"lib/index.d.ts","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../eslint.config.mjs","test":"jest --passWithNoTests --coverage","build":"../../../../scripts/build/build_package.sh HealthLakeConfigContents","watch":"tsc -w","test:package-docs":"../../../../scripts/generate_docs/test_package_docs.sh","test:update-baselines":"UPDATE_BASELINES=true jest --passWithNoTests --testPathPattern='.*\\.diff\\.test\\.ts'"},"version":"1.9.0","_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","_resolved":"/codebuild/output/src553311566/src/out/mdaa/target/package-build/aws-mdaa-healthlake-1.9.0.tgz","_integrity":"sha512-HkHfFsC+gs4rLS/boByJvmWHIxfoski3omN2rWebGkw484BK2htl++swHJz+YKEwPbspatljww6k5F5Anp715g==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"11.7.0","description":"MDAA HealthLake FHIR R4 Datastore module","directories":{},"maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"_nodeVersion":"22.23.2","dependencies":{"ajv":"8.18.0","yaml":"1.10.3","cdk-nag":"2.37.55","constructs":"10.6.0","aws-cdk-lib":"2.261.0","@aws-mdaa/app":"1.9.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.9.0","@aws-mdaa/iam-role-helper":"1.9.0","@aws-mdaa/healthlake-l3-construct":"1.9.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.9.0","typescript-json-schema":"0.68.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/healthlake_1.9.0_1790952173993_0.14166760342358242"}}},"time":{"created":"2026-09-01T18:40:30.507Z","modified":"2026-10-02T14:42:54.232Z","1.8.0":"2026-09-01T18:40:30.893Z","1.8.1":"2026-09-14T20:19:01.537Z","1.9.0":"2026-10-02T14:42:54.081Z"},"bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"description":"MDAA HealthLake FHIR R4 Datastore module","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"readme":"# HealthLake\n\n> **Note:** This documentation is also available in a rendered format [here](https://aws.github.io/modern-data-architecture-accelerator/packages/apps/datalake/healthlake-app/index.html).\n\nDeploys one or more Amazon HealthLake FHIR R4 datastores with customer-managed KMS encryption, per-datastore least-privilege IAM data-access roles for import/export operations, and automatic Glue database metadata resolution. Datastores are configured via a named `datastores` map — each entry becomes a distinct datastore, all sharing a single KMS key. Use this module when you need one or more compliant, production-ready HealthLake datastores for healthcare data interoperability.\n\n---\n\n## Deployed Resources\n\nPer entry in the `datastores` map:\n\n**HealthLake FHIR R4 Datastore** - A fully managed FHIR R4-compliant datastore encrypted with the (shared) customer-managed KMS key for storing and querying healthcare data.\n\n**Datastore Replacement Guard** - A Custom Resource (Lambda-backed) that blocks CloudFormation updates which would replace (delete and recreate) the datastore — see [Datastore Replacement Protection](#datastore-replacement-protection).\n\n**IAM Data-Access Role** - A least-privilege IAM role assumed by the HealthLake service for S3 read/write and KMS encrypt/decrypt operations during import and export jobs.\n\n**Glue Database Resolver** - A construct that derives the auto-created Glue database metadata (name and catalog ID) after datastore creation.\n\n**SSM Parameters** - Nine SSM parameters per datastore: datastore ID, ARN, and endpoint; the data-access role's ARN, ID, and name (plus a `healthlake`-namespaced role-ARN alias); and the Glue database name and catalog ID — all for cross-module consumption.\n\nShared across all datastores in the stack:\n\n**KMS Key** - A single customer-managed KMS key is used to encrypt every datastore. Provide `kmsKeyArn` at the module root to reuse an existing key, or omit it to have the module create one.\n\n---\n\n## Security/Compliance Details\n\nThis module enforces compliance by default with no opt-out for critical security controls:\n\n- **Encryption at Rest** - Customer-managed KMS key (CMK) encryption is mandatory; no unencrypted datastores can be deployed\n- **Least Privilege** - IAM policies are scoped to specific ARNs only; no wildcard resources (`*`) are used anywhere\n- **KMS Grant Control** - `kms:CreateGrant` is restricted with the `GrantIsForAWSResource` condition\n- **Service Trust** - Only `healthlake.amazonaws.com` is permitted in the role trust policy\n- **CDK Nag Validation** - All resources pass AwsSolutions, NIST 800-53, HIPAA, and PCI DSS rulesets\n\n### Datastore Replacement Protection\n\n`AWS::HealthLake::FHIRDatastore` replaces (deletes and recreates) the underlying datastore whenever `DatastoreName`, `DatastoreTypeVersion`, `IdentityProviderConfiguration`, `PreloadDataConfig`, or `SseConfiguration` changes — this is documented AWS CloudFormation behavior, not an MDAA limitation. In practice this means renaming a datastore entry (its `datastores` map key), changing `kmsKeyArn`, toggling `identityProviderConfiguration`, or toggling `preloadSynthea` on an existing datastore would trigger a replacement.\n\n**This module blocks that from happening by default.** Each datastore is guarded by a Custom Resource that compares the previous and current values of `datastoreName`, `kmsKeyArn`, `identityProviderConfiguration`, and `preloadSynthea` on every deploy. If any of these changed, the deployment fails *before* the datastore is touched — no replacement occurs, no data is at risk. `RemovalPolicy.RETAIN` is also applied to every `FHIRDatastore` as defense-in-depth: if a replacement is explicitly acknowledged (see below), the old datastore is detached rather than deleted, surviving as an orphaned AWS resource whose data you must migrate manually.\n\nIf you intend to make one of these changes on purpose (e.g. provisioning a genuinely new datastore under an existing name), set `acknowledgeReplacement: true` on that datastore's configuration for the deploy that makes the change:\n\n```yaml\ndatastores:\n  primary:\n    rawBucketArn: arn:{{partition}}:s3:::example-raw-bucket\n    preloadSynthea: true\n    acknowledgeReplacement: true  # required to allow this change through\n```\n\nRemove `acknowledgeReplacement` (or set it back to `false`) after the acknowledged deploy completes, so the guard resumes blocking unintentional changes.\n\n---\n\n## Configuration\n\n### MDAA Config\n\n```yaml\n# mdaa.yaml\nhealthlake:\n  module: \"@aws-mdaa/healthlake\"\n  config: healthlake-config.yaml\n```\n\n### Module Config Samples and Variants\n\n#### Minimal Configuration\n\nDeploys a HealthLake FHIR R4 datastore with only the required S3 bucket ARN. A customer-managed KMS key is created automatically when not explicitly provided. Use this when you need a basic datastore without sample data or SMART on FHIR authorization.\n\n[sample-config-minimal.yaml](sample_configs/sample-config-minimal.yaml)\n\n```yaml\n--8<-- \"target/docs/packages/apps/datalake/healthlake-app/sample_configs/sample-config-minimal.yaml\"\n```\n\n#### Comprehensive Configuration\n\nCovers all available configuration options including explicit KMS key, Synthea sample data preloading, and SMART on FHIR identity provider configuration. Use this as a reference for the full set of configurable properties.\n\n[sample-config-comprehensive.yaml](sample_configs/sample-config-comprehensive.yaml)\n\n```yaml\n--8<-- \"target/docs/packages/apps/datalake/healthlake-app/sample_configs/sample-config-comprehensive.yaml\"\n```\n\n#### SMART on FHIR Configuration\n\nDeploys a HealthLake FHIR R4 datastore with SMART on FHIR authorization enabled, requiring an OAuth2 token-decoding Lambda ARN. Use this when integrating with a SMART App Launch identity provider for clinical applications or third-party EHR clients.\n\n[sample-config-smart.yaml](sample_configs/sample-config-smart.yaml)\n\n```yaml\n--8<-- \"target/docs/packages/apps/datalake/healthlake-app/sample_configs/sample-config-smart.yaml\"\n```\n","readmeFilename":"README.md"}