Why can't I create a HealthLake data store? - AWS HealthLake

Why can't I create a HealthLake data store?

On November, 14, 2022, HealthLake updated the required IAM permissions needed to create a new data store. If you haven't updated policies attached to the user or role that accesses HealthLake you get the following error.

AccessDeniedException: Insufficient Lake Formation permission(s): Required Database on Catalog

To view updated IAM policy requirements for creating a data store, see AWS managed policy: AmazonHealthLakeFullAccess. For step-by-step directions on how to add these policies to your IAM user or role, see Setting up permissions to start using AWS HealthLake.

To create a data store, you also need use of a symmetrical customer-owned or Amazon-owned KMS key. Make sure you have the correct permissions in your IAM policy. To learn more about AWS KMS, see AWS Key Management Service in the AWS Key Management Service Developer Guide.