בקרת גישה באמצעות IAM

סקירה כללית

ב-Cloud Healthcare API נעשה שימוש בניהול זהויות והרשאות גישה (IAM) לצורך בקרת גישה.

ב-Cloud Healthcare API, אפשר להגדיר את בקרת הגישה ברמת הפרויקט, מערך הנתונים או מאגר הנתונים. לדוגמה, אתם יכולים לתת גישה לכל מערכי הנתונים בפרויקט לקבוצת מפתחים. במאמרים בקרת גישה ובקרת גישה למוצרים אחרים מוסבר איך מגדירים ומשתמשים ב-IAM עם Cloud Healthcare API.

למידע מפורט על IAM והמאפיינים שלו, תוכלו לעיין במסמכי העזרה של IAM. כדאי לקרוא באופן ספציפי את הקטע בנושא ניהול מדיניות IAM.

כדי להפעיל כל method ב-Cloud Healthcare API, למבצע הקריאה החוזרת (caller) צריכות להיות ההרשאות הנדרשות. מידע נוסף זמין במאמרים בנושא הרשאות ותפקידים.

הרשאות

בטבלאות הבאות מפורטות ההרשאות של IAM שמשויכות ל-Cloud Healthcare API. השמות של ה-methods מקוצרים בטבלה. השם המלא של כל method מתחיל ב-projects.locations..

שיטה לאחסון הסכמה ההרשאות הנדרשות
datasets.consentStores.checkDataAccess healthcare.consentStores.checkDataAccess בחנות ההסכמה המבוקשת.
datasets.consentStores.create ‫healthcare.consentStores.create במערך הנתונים הראשי.
datasets.consentStores.delete healthcare.consentStores.delete בחנות ההסכמה המבוקשת.
datasets.consentStores.evaluateUserConsents healthcare.consentStores.evaluateUserConsents בחנות ההסכמה המבוקשת.
datasets.consentStores.get healthcare.consentStores.get בחנות ההסכמה המבוקשת.
datasets.consentStores.getIamPolicy healthcare.consentStores.getIamPolicy בחנות ההסכמה המבוקשת.
datasets.consentStores.list ‫healthcare.consentStores.list במערך הנתונים הראשי.
datasets.consentStores.patch healthcare.consentStores.update בחנות ההסכמה המבוקשת.
datasets.consentStores.queryAccessibleData healthcare.consentStores.queryAccessibleData בחנות ההסכמה המבוקשת.
datasets.consentStores.setIamPolicy healthcare.consentStores.setIamPolicy בחנות ההסכמה המבוקשת.
datasets.consentStores.attributeDefinitions.create healthcare.attributeDefinitions.create בחנות שבה מוצגת בקשת הסכמת ההורים.
datasets.consentStores.attributeDefinitions.delete ‫healthcare.attributeDefinitions.delete במשאב של הגדרת המאפיין המבוקש.
datasets.consentStores.attributeDefinitions.get ‫healthcare.attributeDefinitions.get במשאב של הגדרת המאפיין המבוקש.
datasets.consentStores.attributeDefinitions.list healthcare.attributeDefinitions.list בחנות שבה מוצגת בקשת הסכמת ההורים.
datasets.consentStores.attributeDefinitions.patch ‫healthcare.attributeDefinitions.update במשאב של הגדרת המאפיין המבוקש.
datasets.consentStores.consentArtifacts.create healthcare.consentArtifacts.create בחנות שבה מוצגת בקשת הסכמת ההורים.
datasets.consentStores.consentArtifacts.delete ‫healthcare.consentArtifacts.delete במשאב של ארטיפקט ההסכמה המבוקש.
datasets.consentStores.consentArtifacts.get ‫healthcare.consentArtifacts.get במשאב של ארטיפקט ההסכמה המבוקש.
datasets.consentStores.consentArtifacts.list healthcare.consentArtifacts.list בחנות שבה מוצגת בקשת הסכמת ההורים.
datasets.consentStores.consents.create healthcare.consents.create בחנות שבה מוצגת בקשת הסכמת ההורים.
datasets.consentStores.consents.delete healthcare.consents.delete במשאב ההסכמה המבוקש.
datasets.consentStores.consents.get healthcare.consents.get במשאב ההסכמה המבוקש.
datasets.consentStores.consents.list healthcare.consents.list בחנות שבה מוצגת בקשת הסכמת ההורים.
datasets.consentStores.consents.patch healthcare.consents.update במשאב ההסכמה המבוקש.
datasets.consentStores.consents.revoke healthcare.consents.revoke במשאב ההסכמה המבוקש.
datasets.consentStores.userDataMappings.archive healthcare.userDataMappings.archive במשאב המיפוי של נתוני המשתמש המבוקשים.
datasets.consentStores.userDataMappings.create healthcare.userDataMappings.create בחנות שבה מוצגת בקשת הסכמת ההורים.
datasets.consentStores.userDataMappings.delete healthcare.userDataMappings.delete במשאב המיפוי של נתוני המשתמש המבוקשים.
datasets.consentStores.userDataMappings.get healthcare.userDataMappings.get במשאב המיפוי של נתוני המשתמש המבוקשים.
datasets.consentStores.userDataMappings.list healthcare.userDataMappings.list בחנות שבה מוצגת בקשת הסכמת ההורים.
datasets.consentStores.userDataMappings.patch healthcare.userDataMappings.update במשאב המיפוי של נתוני המשתמש המבוקשים.

שיטות של מערך הנתונים

שיטה של מערכי נתונים ההרשאות הנדרשות
datasets.create ‫healthcare.datasets.create בפרויקט Google Cloud ההורה.
datasets.deidentify
  • ‫healthcare.datasets.deidentify במערך הנתונים של המקור.
  • ‫healthcare.datasets.create בפרויקט Google Cloud שכולל את מערך הנתונים של היעד.
datasets.delete healthcare.datasets.delete במערך הנתונים המבוקש.
datasets.get healthcare.datasets.get במערך הנתונים המבוקש.
datasets.getIamPolicy healthcare.datasets.getIamPolicy במערך הנתונים המבוקש.
datasets.list ‫healthcare.datasets.list בפרויקט Google Cloud ההורה.
datasets.patch healthcare.datasets.update במערך הנתונים המבוקש.
datasets.setIAMPolicy healthcare.datasets.setIamPolicy במערך הנתונים המבוקש.

שיטות לאחסון DICOM

שיטת DICOM store ההרשאות הנדרשות
datasets.dicomStores.create ‫healthcare.dicomStores.create במערך הנתונים הראשי.
datasets.dicomStores.deidentify
  • ‫healthcare.dicomStores.deidentify בחנות DICOM של המקור.
  • ‫healthcare.dicomStores.dicomWebWrite בחנות היעד של DICOM.
datasets.dicomStores.delete ‫healthcare.dicomStores.delete בחנות DICOM המבוקשת.
datasets.dicomStores.export
  • ‫healthcare.dicomStores.export בחנות DICOM המבוקשת.
  • כשמייצאים ל-Cloud Storage: roles/storage.objectAdmin שניתנה לחשבון השירות של סוכן השירות של Cloud Healthcare בפרויקט. הוראות מפורטות זמינות במאמר ייצוא נתונים ל-Cloud Storage.
  • כשמייצאים ל-BigQuery: ההרשאות roles/bigquery.dataEditor ו-roles/bigquery.jobUser מוענקות לחשבון השירות Cloud Healthcare Service Agent של הפרויקט. הוראות מפורטות זמינות במאמר הרשאות BigQuery למאגר DICOM.
datasets.dicomStores.get ‫healthcare.dicomStores.get בחנות DICOM המבוקשת.
datasets.dicomStores.getIamPolicy ‫healthcare.dicomStores.getIamPolicy ב-DICOM store המבוקש.
datasets.dicomStores.import
  • ‫healthcare.dicomStores.import בחנות DICOM המבוקשת.
  • roles/storage.objectViewer שמוקצות לחשבון השירות Cloud Healthcare Service Agent של הפרויקט. הוראות מפורטות זמינות במאמר בנושא ייבוא נתונים מ-Cloud Storage.
datasets.dicomStores.list ‫healthcare.dicomStores.list במערך הנתונים הראשי.
datasets.dicomStores.patch ‫healthcare.dicomStores.update בחנות DICOM המבוקשת.
datasets.dicomStores.searchForInstances ‫healthcare.dicomStores.dicomWebRead ב-DICOM store המבוקש.
datasets.dicomStores.searchForSeries ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.searchForStudies ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.setIamPolicy ‫healthcare.dicomStores.setIamPolicy ב-DICOM store המבוקש.
datasets.dicomStores.storeInstances ‫healthcare.dicomStores.dicomWebWrite ב-DICOM store המבוקש.
datasets.dicomStores.studies.delete ‫healthcare.dicomStores.dicomWebDelete ב-DICOM store המבוקש.
datasets.dicomStores.studies.retrieveMetadata ‫healthcare.dicomStores.dicomWebRead ב-DICOM store המבוקש.
datasets.dicomStores.studies.retrieveStudy ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.studies.searchForInstances ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.studies.searchForSeries ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.studies.storeInstances ‫healthcare.dicomStores.dicomWebWrite ב-DICOM store המבוקש.
datasets.dicomStores.studies.updateInstances ‫healthcare.dicomStores.dicomWebUpdate בחנות DICOM המבוקשת.
datasets.dicomStores.studies.updateMetadata ‫healthcare.dicomStores.dicomWebUpdate בחנות DICOM המבוקשת.
datasets.dicomStores.studies.series.delete ‫healthcare.dicomStores.dicomWebDelete ב-DICOM store המבוקש.
datasets.dicomStores.studies.series.retrieveMetadata ‫healthcare.dicomStores.dicomWebRead ב-DICOM store המבוקש.
datasets.dicomStores.studies.series.retrieveSeries ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.studies.series.searchForInstances ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.studies.series.updateMetadata ‫healthcare.dicomStores.dicomWebUpdate ב-DICOM store המבוקש.
datasets.dicomStores.studies.series.instances.delete ‫healthcare.dicomStores.dicomWebDelete ב-DICOM store המבוקש.
datasets.dicomStores.studies.series.instances.retrieveInstance ‫healthcare.dicomStores.dicomWebRead ב-DICOM store המבוקש.
datasets.dicomStores.studies.series.instances.retrieveMetadata ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.studies.series.instances.retrieveRendered ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.studies.series.instances.updateMetadata ‫healthcare.dicomStores.dicomWebUpdate ב-DICOM store המבוקש.
datasets.dicomStores.studies.series.instances.frames.retrieveFrames ‫healthcare.dicomStores.dicomWebRead ב-DICOM store המבוקש.
datasets.dicomStores.studies.series.instances.frames.retrieveRendered ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.
datasets.dicomStores.studies.series.instances.bulkdata.retrieveBulkdata ‫healthcare.dicomStores.dicomWebRead בחנות DICOM המבוקשת.

שיטות של חנות FHIR

שיטת FHIR store ההרשאות הנדרשות
datasets.fhirStores.applyConsents ‫healthcare.fhirStores.applyConsents במשאב המבוקש של חנות FHIR.
datasets.fhirStores.applyAdminConsents ‫healthcare.fhirStores.applyConsents במשאב המבוקש של חנות FHIR.
datasets.fhirStores.configureSearch ‫healthcare.fhirStores.configureSearch בחנות FHIR המבוקשת.
datasets.fhirStores.create ‫healthcare.fhirStores.create במערך הנתונים הראשי.
datasets.fhirStores.deidentify
  • ‫healthcare.fhirStores.deidentify בחנות המקורית של FHIR.
  • ‫healthcare.fhirResources.update בחנות היעד של FHIR.
datasets.fhirStores.delete ‫healthcare.fhirStores.delete בחנות FHIR המבוקשת.
datasets.fhirStores.explainDataAccess ‫healthcare.fhirStores.explainDataAccess במשאב המבוקש של חנות FHIR.
datasets.fhirStores.export
  • ‫healthcare.fhirStores.export בחנות FHIR המבוקשת.
  • כשמייצאים ל-Cloud Storage: ההרשאות storage.objects.create,‏ storage.objects.delete ו-storage.objects.list מוענקות לחשבון השירות של סוכן שירות Cloud Healthcare בפרויקט. הוראות מפורטות זמינות במאמר בנושא ייצוא משאבי FHIR ל-Cloud Storage.
  • כשמייצאים ל-BigQuery: ההרשאות roles/bigquery.dataEditor ו-roles/bigquery.jobUser מוענקות לחשבון השירות Cloud Healthcare Service Agent של הפרויקט. הוראות מפורטות זמינות במאמר הרשאות ב-BigQuery למאגר FHIR.
datasets.fhirStores.get ‫healthcare.fhirStores.get בחנות FHIR המבוקשת.
datasets.fhirStores.getFHIRStoreMetrics ‫healthcare.fhirStores.get בחנות FHIR המבוקשת.
datasets.fhirStores.getIamPolicy ‫healthcare.fhirStores.getIamPolicy בחנות FHIR המבוקשת.
datasets.fhirStores.import
  • ‫healthcare.fhirStores.import בחנות FHIR המבוקשת.
  • ‫storage.objects.get ו-storage.objects.list שהוקצו לחשבון השירות Cloud Healthcare Service Agent של הפרויקט. הוראות מפורטות זמינות במאמר בנושא ייבוא משאבי FHIR מ-Cloud Storage.
datasets.fhirStores.list ‫healthcare.fhirStores.list במערך הנתונים הראשי.
datasets.fhirStores.patch ‫healthcare.fhirStores.update בחנות FHIR המבוקשת.
datasets.fhirStores.rollback ‫healthcare.fhirStores.rollback בחנות FHIR המבוקשת.
datasets.fhirStores.setIamPolicy ‫healthcare.fhirStores.setIamPolicy בחנות FHIR המבוקשת.
datasets.fhirStores.fhir.Encounter-everything healthcare.fhirResources.get בכל משאב שמוחזר.
datasets.fhirStores.fhir.Observation-lastn ‫healthcare.fhirStores.searchResources בחנות FHIR הראשית.
datasets.fhirStores.fhir.Patient-everything healthcare.fhirResources.get בכל משאב שמוחזר.
datasets.fhirStores.fhir.Resource-purge ‫healthcare.fhirResources.purge במשאב המבוקש של חנות FHIR.
datasets.fhirStores.fhir.capabilities ‫healthcare.fhirStores.get בחנות FHIR המבוקשת.
datasets.fhirStores.fhir.conditionalDelete
  • ‫healthcare.fhirStores.searchResources בחנות FHIR הראשית.
  • ‫healthcare.fhirResources.delete במשאב המבוקש של חנות FHIR.
datasets.fhirStores.fhir.conditionalPatch
  • ‫healthcare.fhirStores.searchResources בחנות FHIR הראשית.
  • ‫healthcare.fhirResources.patch במשאב המבוקש של חנות FHIR.
datasets.fhirStores.fhir.conditionalUpdate
  • ‫healthcare.fhirStores.searchResources בחנות FHIR הראשית.
  • ‫healthcare.fhirResources.update במשאב המבוקש של חנות FHIR.
datasets.fhirStores.fhir.create
  • לאינטראקציות של יצירה מותנית: healthcare.fhirResources.create ו-healthcare.fhirStores.searchResources בחנות FHIR של ההורה.
  • לגבי אינטראקציות של יצירה: healthcare.fhirResources.create בחנות FHIR הראשית.
datasets.fhirStores.fhir.delete ‫healthcare.fhirResources.delete במשאב המבוקש של חנות FHIR.
datasets.fhirStores.fhir.executeBundle ‫healthcare.fhirResources.executeBundle בחנות FHIR המבוקשת, והרשאות נוספות (כמו healthcare.fhirResources.create ו-healthcare.fhirResources.update) שמתאימות לפעולות נפרדות בחבילה. אם למתקשר ב-API יש הרשאות healthcare.fhirResources.create אבל לא הרשאות healthcare.fhirResources.update, הוא יכול להפעיל רק חבילות שמכילות פעולות healthcare.fhirResources.create.
datasets.fhirStores.fhir.history ‫healthcare.fhirResources.get במשאב המבוקש של מאגר FHIR ובכל אחת מהגרסאות שלו.
datasets.fhirStores.fhir.patch ‫healthcare.fhirResources.patch במשאב המבוקש של חנות FHIR.
datasets.fhirStores.fhir.read ‫healthcare.fhirResources.get במשאב המבוקש של חנות FHIR.
datasets.fhirStores.fhir.search ‫healthcare.fhirStores.searchResources בחנות FHIR הראשית.
datasets.fhirStores.fhir.update ‫healthcare.fhirResources.update במשאב המבוקש של חנות FHIR.
datasets.fhirStores.fhir.vread ‫healthcare.fhirResources.get בגרסת משאב מאגר FHIR המבוקשת.
datasets.fhirStores.fhir.Patient-consent-enforcement-status ‫healthcare.fhirResources.get במשאב המטופל במאגר FHIR המבוקש.
datasets.fhirStores.fhir.Consent-enforcement-status ‫healthcare.fhirResources.get במשאב ההסכמה של מאגר FHIR המבוקש.

שיטות של חנויות HL7v2

שיטה לאחסון נתונים בפורמט HL7v2 ההרשאות הנדרשות
datasets.hl7V2Stores.create ‫healthcare.hl7V2Stores.create במערך הנתונים הראשי.
datasets.hl7V2Stores.delete healthcare.hl7V2Stores.delete בחנות HL7v2 המבוקשת.
datasets.hl7V2Stores.export healthcare.hl7V2Stores.export בחנות HL7v2 המבוקשת.
datasets.hl7V2Stores.get healthcare.hl7V2Stores.get בחנות HL7v2 המבוקשת.
datasets.hl7V2Stores.import healthcare.hl7V2Stores.import בחנות HL7v2 המבוקשת.
datasets.hl7V2Stores.list ‫healthcare.hl7V2Stores.list במערך הנתונים הראשי.
datasets.hl7V2Stores.patch healthcare.hl7V2Stores.update בחנות HL7v2 המבוקשת.
datasets.hl7V2Stores.getIamPolicy healthcare.hl7V2Stores.getIamPolicy בחנות HL7v2 המבוקשת.
datasets.hl7V2Stores.setIamPolicy healthcare.hl7V2Stores.setIamPolicy בחנות HL7v2 המבוקשת.
datasets.hl7V2Stores.messages.create ‫healthcare.hl7V2Messages.create בחנות הראשית ב-HL7v2.
datasets.hl7V2Stores.messages.delete ‫healthcare.hl7V2Messages.delete בהודעה של חנות HL7v2 המבוקשת.
datasets.hl7V2Stores.messages.get ‫healthcare.hl7V2Messages.get בהודעה של חנות HL7v2 המבוקשת.
datasets.hl7V2Stores.messages.ingest ‫healthcare.hl7V2Messages.ingest בהודעה של חנות HL7v2 המבוקשת.
datasets.hl7V2Stores.messages.list ‫healthcare.hl7V2Messages.list בחנות הראשית ב-HL7v2.
datasets.hl7V2Stores.messages.patch ‫healthcare.hl7V2Messages.update בהודעה של חנות HL7v2 המבוקשת.

שיטות מיקום מודעה

שיטת המיקום ההרשאות הנדרשות
locations.get healthcare.locations.get במיקום המבוקש.
locations.list ‫healthcare.locations.list בפרויקט Google Cloud ההורה.

שיטות של Healthcare Natural Language API

שיטת Healthcare Natural Language API ההרשאות הנדרשות
nlp.analyzeEntities healthcare.nlpservice.analyzeEntities

שיטות הפעלה

שיטת הפעולה ההרשאה הנדרשת
datasets.operations.get ‫healthcare.operations.get במערך הנתונים המבוקש.
datasets.operations.list ‫healthcare.operations.list במערך הנתונים המבוקש.
datasets.operations.cancel healthcare.operations.cancel במערך הנתונים המבוקש.

שיטות להסרת פרטי זיהוי

שיטה להסרת פרטי זיהוי ההרשאה הנדרשת
services.deidentify.deidentifyDicomInstance healthcare.deidentify.run
services.deidentify.deidentifyFhirResource healthcare.deidentify.run

תפקידים

בטבלאות הבאות מפורטים תפקידי IAM ב-Cloud Healthcare API, כולל ההרשאות שמשויכות לכל תפקיד. התפקידים roles/owner, ‏roles/editor ו-roles/viewer כוללים הרשאות לשירותים אחרים של Google Cloud . מידע נוסף על תפקידים מופיע במאמר הסבר על תפקידים.

תפקיד מאגר ההסכמה הרשאות

(roles/healthcare.consentStoreViewer)

הצגת רשימה של מאגרי מידע להסכמה במערך נתונים.

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.consentStoreAdmin)

ניהול חנויות שדורשות הסכמה.

healthcare.consentStores.*

  • healthcare.consentStores.checkDataAccess
  • healthcare.consentStores.create
  • healthcare.consentStores.delete
  • healthcare.consentStores.evaluateUserConsents
  • healthcare.consentStores.get
  • healthcare.consentStores.getIamPolicy
  • healthcare.consentStores.list
  • healthcare.consentStores.queryAccessibleData
  • healthcare.consentStores.setIamPolicy
  • healthcare.consentStores.update

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

תפקידים שקשורים להסכמה

תפקיד ההסכמות הרשאות

(roles/healthcare.attributeDefinitionReader)

קריאת אובייקטים של AttributeDefinition בחנות הסכמה.

healthcare.attributeDefinitions.get

healthcare.attributeDefinitions.list

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.attributeDefinitionEditor)

עריכה של אובייקטים מסוג AttributeDefinition.

healthcare.attributeDefinitions.*

  • healthcare.attributeDefinitions.create
  • healthcare.attributeDefinitions.delete
  • healthcare.attributeDefinitions.get
  • healthcare.attributeDefinitions.list
  • healthcare.attributeDefinitions.update

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.consentArtifactReader)

קריאת אובייקטים מסוג ConsentArtifact בחנות הסכמה.

healthcare.consentArtifacts.get

healthcare.consentArtifacts.list

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.consentArtifactEditor)

עריכת אובייקטים מסוג ConsentArtifact.

healthcare.consentArtifacts.create

healthcare.consentArtifacts.get

healthcare.consentArtifacts.list

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.consentArtifactAdmin)

ניהול אובייקטים מסוג ConsentArtifact.

healthcare.consentArtifacts.*

  • healthcare.consentArtifacts.create
  • healthcare.consentArtifacts.delete
  • healthcare.consentArtifacts.get
  • healthcare.consentArtifacts.list

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.consentReader)

קריאת אובייקטים של הסכמה בחנות הסכמה.

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.consents.get

healthcare.consents.list

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.consentEditor)

עריכת אובייקטים של הסכמה.

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.consents.*

  • healthcare.consents.activate
  • healthcare.consents.create
  • healthcare.consents.delete
  • healthcare.consents.get
  • healthcare.consents.list
  • healthcare.consents.reject
  • healthcare.consents.revoke
  • healthcare.consents.update

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.userDataMappingReader)

קריאת אובייקטים של UserDataMapping בחנות הסכמה.

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

healthcare.userDataMappings.get

healthcare.userDataMappings.list

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.userDataMappingEditor)

עריכת אובייקטים של UserDataMapping.

healthcare.consentStores.checkDataAccess

healthcare.consentStores.evaluateUserConsents

healthcare.consentStores.get

healthcare.consentStores.list

healthcare.consentStores.queryAccessibleData

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

healthcare.userDataMappings.*

  • healthcare.userDataMappings.archive
  • healthcare.userDataMappings.create
  • healthcare.userDataMappings.delete
  • healthcare.userDataMappings.get
  • healthcare.userDataMappings.list
  • healthcare.userDataMappings.update

resourcemanager.projects.get

resourcemanager.projects.list

תפקידים במערכי נתונים

תפקיד במערכי נתונים הרשאות

(roles/healthcare.datasetViewer)

הצגת רשימה של מערכי הנתונים של שירותי הבריאות בפרויקט.

healthcare.datasets.get

healthcare.datasets.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.datasetAdmin)

ניהול מערכי נתונים רפואיים.

healthcare.datasets.*

  • healthcare.datasets.create
  • healthcare.datasets.deidentify
  • healthcare.datasets.delete
  • healthcare.datasets.get
  • healthcare.datasets.getIamPolicy
  • healthcare.datasets.list
  • healthcare.datasets.setIamPolicy
  • healthcare.datasets.update

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.*

  • healthcare.operations.cancel
  • healthcare.operations.get
  • healthcare.operations.list

resourcemanager.projects.get

resourcemanager.projects.list

תפקידים במאגר DICOM

תפקיד מאגר DICOM הרשאות

(roles/healthcare.dicomStoreViewer)

הצגת רשימה של חנויות DICOM במערך נתונים.

healthcare.datasets.get

healthcare.datasets.list

healthcare.dicomStores.get

healthcare.dicomStores.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.dicomStoreAdmin)

ניהול חנויות DICOM.

healthcare.datasets.get

healthcare.datasets.list

healthcare.dicomStores.create

healthcare.dicomStores.deidentify

healthcare.dicomStores.delete

healthcare.dicomStores.dicomWebDelete

healthcare.dicomStores.get

healthcare.dicomStores.getIamPolicy

healthcare.dicomStores.list

healthcare.dicomStores.setIamPolicy

healthcare.dicomStores.update

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.cancel

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.dicomViewer)

אחזור תמונות DICOM ממאגר DICOM.

healthcare.datasets.get

healthcare.datasets.list

healthcare.dicomStores.dicomWebRead

healthcare.dicomStores.export

healthcare.dicomStores.get

healthcare.dicomStores.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.dicomEditor)

עריכה של תמונות DICOM בנפרד או בכמות גדולה.

healthcare.datasets.get

healthcare.datasets.list

healthcare.dicomStores.dicomWebDelete

healthcare.dicomStores.dicomWebRead

healthcare.dicomStores.dicomWebUpdate

healthcare.dicomStores.dicomWebWrite

healthcare.dicomStores.export

healthcare.dicomStores.get

healthcare.dicomStores.import

healthcare.dicomStores.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.cancel

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

תפקידים בחנות FHIR

תפקיד בחנות FHIR הרשאות

(roles/healthcare.fhirStoreViewer)

הצגת רשימה של מאגרי FHIR במערך נתונים.

healthcare.datasets.get

healthcare.datasets.list

healthcare.fhirStores.get

healthcare.fhirStores.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.fhirStoreAdmin)

ניהול מאגרי משאבים ב-FHIR.

healthcare.datasets.get

healthcare.datasets.list

healthcare.fhirResources.purge

healthcare.fhirStores.applyConsents

healthcare.fhirStores.bulkDelete

healthcare.fhirStores.configureSearch

healthcare.fhirStores.create

healthcare.fhirStores.deidentify

healthcare.fhirStores.delete

healthcare.fhirStores.deleteFhirOperation

healthcare.fhirStores.explainDataAccess

healthcare.fhirStores.export

healthcare.fhirStores.get

healthcare.fhirStores.getFhirOperation

healthcare.fhirStores.getIamPolicy

healthcare.fhirStores.import

healthcare.fhirStores.list

healthcare.fhirStores.rollback

healthcare.fhirStores.setIamPolicy

healthcare.fhirStores.update

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.cancel

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.fhirResourceReader)

לקרוא ולחפש משאבי FHIR.

healthcare.datasets.get

healthcare.datasets.list

healthcare.fhirResources.get

healthcare.fhirResources.translateConceptMap

healthcare.fhirStores.executeBundle

healthcare.fhirStores.get

healthcare.fhirStores.list

healthcare.fhirStores.searchResources

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.fhirResourceEditor)

יצירה, מחיקה, עדכון, קריאה וחיפוש של משאבי FHIR.

healthcare.datasets.get

healthcare.datasets.list

healthcare.fhirResources.create

healthcare.fhirResources.delete

healthcare.fhirResources.get

healthcare.fhirResources.patch

healthcare.fhirResources.translateConceptMap

healthcare.fhirResources.update

healthcare.fhirStores.executeBundle

healthcare.fhirStores.get

healthcare.fhirStores.list

healthcare.fhirStores.searchResources

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.cancel

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

תפקידים בחנויות HL7v2

תפקיד בחנות HL7v2 הרשאות

(roles/healthcare.hl7V2StoreViewer)

הצגת החנויות ב-HL7v2 במערך נתונים.

healthcare.datasets.get

healthcare.datasets.list

healthcare.hl7V2Stores.get

healthcare.hl7V2Stores.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.hl7V2StoreAdmin)

ניהול החנויות ב-HL7v2.

healthcare.datasets.get

healthcare.datasets.list

healthcare.hl7V2Stores.*

  • healthcare.hl7V2Stores.create
  • healthcare.hl7V2Stores.delete
  • healthcare.hl7V2Stores.export
  • healthcare.hl7V2Stores.get
  • healthcare.hl7V2Stores.getIamPolicy
  • healthcare.hl7V2Stores.import
  • healthcare.hl7V2Stores.list
  • healthcare.hl7V2Stores.rollback
  • healthcare.hl7V2Stores.setIamPolicy
  • healthcare.hl7V2Stores.update

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.cancel

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.hl7V2Ingest)

מטמיע הודעות של HL7v2 שהתקבלו מרשת מקור.

healthcare.datasets.get

healthcare.datasets.list

healthcare.hl7V2Messages.ingest

healthcare.hl7V2Stores.get

healthcare.hl7V2Stores.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.hl7V2Consumer)

הצגת רשימה וקריאה של הודעות של HL7v2, עדכון תוויות של הודעות ופרסום הודעות חדשות.

healthcare.datasets.get

healthcare.datasets.list

healthcare.hl7V2Messages.create

healthcare.hl7V2Messages.get

healthcare.hl7V2Messages.list

healthcare.hl7V2Messages.update

healthcare.hl7V2Stores.get

healthcare.hl7V2Stores.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/healthcare.hl7V2Editor)

גישת קריאה, כתיבה ומחיקה של הודעות של HL7v2.

healthcare.datasets.get

healthcare.datasets.list

healthcare.hl7V2Messages.*

  • healthcare.hl7V2Messages.create
  • healthcare.hl7V2Messages.delete
  • healthcare.hl7V2Messages.get
  • healthcare.hl7V2Messages.ingest
  • healthcare.hl7V2Messages.list
  • healthcare.hl7V2Messages.update

healthcare.hl7V2Stores.get

healthcare.hl7V2Stores.list

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.operations.cancel

healthcare.operations.get

resourcemanager.projects.get

resourcemanager.projects.list

תפקידים ב-Healthcare Natural Language API

תפקיד Healthcare Natural Language API הרשאות

(roles/healthcare.nlpServiceViewer)

חילוץ וניתוח של ישויות רפואיות מטקסט נתון.

healthcare.locations.*

  • healthcare.locations.get
  • healthcare.locations.list

healthcare.nlpservice.analyzeEntities

resourcemanager.projects.get

resourcemanager.projects.list

סוכן שירות של Cloud Healthcare

‫Cloud Healthcare Service Agent הוא חשבון שירות משותף בפרויקט שמשמש את Cloud Healthcare API כדי ליצור אינטראקציה עם משאבים אחרים ב-Google Cloud.

לדוגמה, סוכן השירות הזה משמש לקריאה ולכתיבה בקטגוריות של Cloud Storage, לכתיבה ב-BigQuery ולפרסום הודעות ב-Pub/Sub מ-Cloud Healthcare API.

כדי לבצע את הפעולות שצוינו למעלה, צריך לתת לסוכן Cloud Healthcare Service גישה לדלי Cloud Storage, למערך הנתונים ב-BigQuery או לנושא ב-Pub/Sub הרלוונטיים.

כשיוצרים מודל הרשאות לפרויקט, חשוב לזכור שהענקת אחד מהתפקידים שמפורטים בהמשך מאפשרת למשתמש להפעיל פעולות שפועלות כסוכן Cloud Healthcare Service ולקבל גישה לכל הנתונים שהסוכן יכול לגשת אליהם:

  • roles/healthcare.consentStoreAdmin
  • roles/healthcare.consentStoreViewer
  • roles/healthcare.dicomStoreEditor
  • roles/healthcare.dicomStoreViewer
  • roles/healthcare.fhirStoreAdmin
  • roles/healthcare.hl7V2StoreAdmin

באופן דומה, הקצאת ההרשאות הבאות לתפקידים בהתאמה אישית תאפשר למשתמש להפעיל פעולות שירוצו בתור הסוכן של Cloud Healthcare Service:

  • healthcare.consentStores.queryAccessibleData
  • healthcare.dicomStores.create
  • healthcare.dicomStores.update
  • healthcare.dicomStores.import
  • healthcare.dicomStores.export
  • healthcare.fhirStores.create
  • healthcare.fhirStores.update
  • healthcare.fhirStores.import
  • healthcare.fhirStores.export
  • healthcare.hl7V2Stores.create
  • healthcare.hl7V2Stores.update

לדוגמה:

  • אם למשתמש יש הרשאות ייבוא, הוא יכול להריץ פעולות שמתבצעות בתור הסוכן של Cloud Healthcare Service, אם הפעולות האלה ניגשות לדלי Cloud Storage שלסוכן Cloud Healthcare Service יש הרשאת קריאה אליהם.
  • אם למשתמש יש הרשאות ייצוא, הוא יכול להריץ פעולות שפועלות בתור סוכן שירות Cloud Healthcare אם הפעולות האלה ניגשות לקטגוריה שלסוכן השירות יש הרשאת כתיבה אליה.
  • משתמש שיש לו הרשאות ליצור או לעדכן מאגר נתונים יכול להגדיר יעדים של התראות Pub/Sub או יעדים של סטרימינג ב-BigQuery שנשלחים על ידי סוכן Cloud Healthcare Service כשמתבצעים שינויים במאגר הנתונים.

מומלץ להשתמש בכמה פרויקטים כדי לבודד עוד יותר את ההרשאות שניתנות לסוכן השירות של Cloud Healthcare.