
Shosp typical implementation process:
Initial Planning: The process begins with a planning session where the consultant and clinic align expectations, define objectives, and set a project timeline. The consultant analyzes clinic operations to identify which Shosp features will best meet specific goals.
Preparatory Phase: The Shosp team prepares customized tutorials, content, and onboarding materials tailored to the clinic’s size and workflow. This phase ensures that all necessary training and instructional resources are ready before live implementation.
Application and Live Training: The core implementation phase involves interactive training sessions where staff learn to navigate, configure, and use Shosp’s modules effectively. Participants can ask questions, share feedback, and adjust workflows with support from Shosp specialists.
Testing and Goal Setting: During and after hands-on training, measurable goals and performance metrics are established to monitor adoption and success (e.g., reducing patient no-shows or improving billing accuracy).
Shosp platform can be customized extensively to fit specific business and clinical needs. The system is built around a flexible, modular structure that allows clinics, hospitals, and specialists to tailor workflows, digital forms, and service processes to their operational model.
Custom Medical Records: Shosp enables clinics to create fully personalized electronic medical record (EMR) templates. Providers can configure electronic forms (anamnesis, prescriptions, certificates, and protocols) with custom fields, single or multiple selections, text blocks, and date fields. These templates allow professionals to digitize their paper-based workflows without altering their preferred consultation style.
Dynamic Field Configuration: Users can modify field behavior across modules, including marking necessary entry fields as required, hidden, or conditional. This ensures compliance protocols and complete data capture consistency, adapting to complex clinic procedures.
Automation and Workflow Adjustments: The system supports automation triggered by specific events—such as appointment confirmations, billing finalization, or treatment completions—allowing administrators to program tailored actions to suit operational preferences or compliance needs.
Custom Financial Parameters: Financial modules are configurable to reflect each clinic’s accounting structure. Clinics can create custom chart of accounts, cost centers, payment intervals, and installment models, ensuring reporting aligns with the organization’s financial workflow.
Integration and Extensibility: Through its developer API (documented under “API para desenvolvedores”), clinics can connect external systems, business intelligence tools, CRMs, and payment processors. This allows expansion into broader enterprise ecosystems without losing control over data flow.
Interface Personalization: Shosp provides interface-level customization such as clinic logos, color schemes, and screen preferences for dashboards, patient displays, and reception panels. Users can also add clinic-specific educational videos or marketing content to digital displays and communication panels.
Scheduling and Room Customization: Multi-location and multi-specialty clinics can configure appointment settings, consultation types, service durations, and room allocations independently for each branch or department.
User Access and Role Control: Administrators can set granular permissions, define professional hierarchies (doctors, assistants, receptionists), and determine data access levels, ensuring each professional views only relevant information.
Custom Patient Communication: Clinics can personalize communication templates for WhatsApp, SMS, and email with their own branding, tone, scheduling logic, and automated triggers to match specific patient engagement strategies.
Shosp provides a structured and highly interactive training and support program designed to ensure a smooth transition for clinics adopting the platform.
Comprehensive Training Model: Shosp offers both collective and personalized training options. Collective training sessions give new users a broad overview of system functionality and practical use cases, while personalized consulting programs allow clinics to focus on their specific operational challenges and configuration needs.
Consulting-Based Onboarding: Each new implementation includes a dedicated consultant who works with the clinic to align goals, plan activities, and guide the team step by step. The process follows four phases—Planning, Preparatory, Application, and Finalization—ensuring the clinic understands every module before going live.
Flexible Consultation Packages: Training duration varies depending on clinic size.
Small clinics (up to 5 professionals): Approximately 4 hours of consulting and training.
Medium clinics (6–15 professionals): Around 8 hours of in-depth onboarding.
Large clinics (16+ professionals): Up to 14 hours of personalized support, including advanced workflow optimization.
Ongoing User Support: Beyond training, Shosp maintains a specialized customer support center with consultants available to resolve technical or functional issues as they arise. Support operates through multiple communication channels with a close, client-centered approach designed to deliver fast responses and tailored solutions.
Follow-Up and Performance Monitoring: After initial implementation, Shosp’s Customer Success team conducts follow-up meetings to ensure satisfaction, resolve operational questions, and confirm that clinics are achieving measurable efficiency results.
Shosp implements a layered security program aligned with Brazilian medical regulations to protect clinical and patient data across its web and mobile applications. The platform emphasizes compliance with CFM and SBIS recommendations, strong encryption, certified digital signatures, audited logging, and resilient cloud infrastructure to ensure confidentiality, integrity, and availability of health information.
Regulatory alignment: Shosp states it follows the Federal Council of Medicine (CFM) and SBIS protocol recommendations for medical software security and legal validity of digital records, providing a compliance baseline for telemedicine and EMR use in Brazil.
Digital signatures with legal validity: The system supports ICP‑Brasil digital certificates for signing clinical documents, prescriptions, and telemedicine records, guaranteeing juridical validity and non‑repudiation of medical artifacts stored in the patient record.
Data encryption: Clinical data and teleconsultation media are stored in encrypted environments, with emphasis on encrypting sensitive health records so only authorized professionals can access them during care and review workflows.
Secure telemedicine recordings and logs: Video and audio from teleconsultations can be recorded directly into the EMR; access and activity logs are “duly saved,” providing an auditable trail for security oversight and medico‑legal defensibility.
Cloud resilience and backups: Telemedicine and EMR data are hosted in the cloud with real‑time backups; replicas are maintained across at least two additional data centers on different continents to improve fault tolerance and disaster recovery posture.
Access controls and least‑privilege: The platform enforces authenticated, role‑based access so only permitted staff view or modify records, supporting privacy controls within the EMR for sensitive data segments.
Mobile app data safety: Shosp’s Android listing details data safety practices; updates and permissions are disclosed through the Play Store, reflecting mobile privacy governance and ongoing maintenance of app security practices.
Consent management: Before teleconsultations, patients must accept an in‑platform informed consent term, embedding privacy acknowledgment and legal authorization into the workflow to support regulatory compliance and patient rights.
Infrastructure and vendor hardening: Shosp partners with a qualified certificate authority (Soluti) for cloud A3 digital certificates and leverages Amazon Web Services for hosting, aligning with industry‑standard security controls at the infrastructure layer.
Shosp, developed by Shosp Tecnologia da Informação Ltda., follows a continuous and agile update cycle focusing on system reliability, security, and feature optimization. While the company does not publish a fixed release calendar, available data from its mobile app releases, customer documentation, and update notes show that Shosp updates its platform every few weeks to months, typically including bug fixes, interface refinements, and performance upgrades.
Update Frequency: Shosp’s update timeline reflects an incremental cadence aligned with clinical compliance and product enhancements. For instance, its Android app was last updated on September 23 2024, and prior versions show similar mid‑quarter updates, indicating an active bi‑monthly or quarterly release rhythm driven by stability improvements and integration support.
Update Management: All updates are managed automatically through the cloud, meaning users do not need to manually install new versions. Clinics benefit from seamless rollouts with minimal downtime, since updates are deployed centrally from Shosp’s secure servers. Desktop users on the web version receive patches at login, while mobile updates are delivered through the Google Play and Apple App Store channels, ensuring compatibility across devices.
Bug Fixes and Optimizations: Typical update release notes highlight bug corrections, UI enhancements, compatibility adjustments for Android/iOS frameworks, and workflow improvements for modules such as telemedicine, billing, and appointment scheduling. Shosp’s development team monitors user feedback and deploys fixes dynamically to avoid disruptions in clinical operations.
Security and Compliance Upgrades: Updates frequently include security patches to reinforce LGPD (Brazilian General Data Protection Law) compliance, encryption standards, and security certifications, keeping patient data protection measures in sync with the latest federal healthcare and privacy regulations.
Quality Assurance Process: Before production release, updates pass through internal testing phases—functional validation, usability checks, and compliance inspection with CFM and SBIS standards—to maintain medical software certification consistency. Shosp’s technical team manages rollback safeguards to prevent errors during launch.
Customer Communication: Clients are notified of new functionalities and key platform changes by email bulletins, in‑app notifications, or onboarding webinars, allowing clinics to easily adapt to interface or workflow modifications. Update support is also provided by the Customer Success team to ensure smooth adoption.
Shosp’s policy on data ownership and portability follows Brazil’s LGPD (Lei Geral de Proteção de Dados / General Data Protection Law) principles, ensuring users and clinics maintain ownership and control over all information stored or processed through the platform. The company explicitly defines that data generated within its system belongs to the clinic or professional user, while Shosp acts solely as a data processor, responsible for secure storage, transmission, and compliance with privacy standards.
Data Ownership: Clinics and healthcare professionals retain full ownership rights over patient and operational data collected, stored, or managed through Shosp’s platform. Shosp’s role is limited to securely hosting and processing this data, with no authorization to transfer or commercially use it. This setup aligns with the LGPD framework, designating the clinic as the “data controller” and Shosp as the “data operator”.
Legal and Security Foundations: The platform adheres to LGPD, CFM (Federal Council of Medicine), and SBIS (Brazilian Health Informatics Society) protocols to maintain data confidentiality, purpose limitation, and lawful processing. Systems employ encryption, access restriction, and certification under ICP‑Brasil for verified digital signatures in electronic health record transactions, ensuring patient files have juridical validity and auditability without physical paperwork.
Data Portability Rights: In line with Article 18 and 19 of LGPD, clinics and users can request an export of their stored data in structured, machine‑readable formats such as XML or CSV. These exports enable migration to another provider or private archive at any point. Shosp’s systems are built to make records, financial data, and appointment logs portable while maintaining patient confidentiality.
Right of Access and Deletion: Clinicians and patients have the right to request access, correction, or deletion of their personal data. Shosp provides mechanisms through the account dashboard or support team to deliver data copies or remove outdated information, except when retention is required for compliance or audit purposes.
No Third‑Party Data Sharing: The company confirms it does not sell, rent, or share user or patient data with third parties. The data safety declaration in its Google Play listing also shows that Shosp does not collect unnecessary personal information or engage in unauthorized data sharing with any external entities.
Contractual Safeguards: Service contracts between Shosp and client clinics specify ownership and define post‑termination conditions. If a clinic discontinues service, Shosp grants a defined window to export all clinical and financial records before data is permanently anonymized or deleted from its servers to maintain privacy compliance.
The contract renewal and cancellation terms for Shosp operate under a typical SaaS (Software as a Service) subscription model. The following points summarize the company’s contractual, financial, and data-handling conditions based on the official Shosp Terms of Use and verified user experiences.
The agreement takes effect once the customer accepts it electronically and remains active indefinitely while payments are current.
Subscriptions renew automatically based on the billing cycle (monthly, quarterly, semi-annual, or annual). No renewal confirmation is required.
Price adjustments may occur once per year, according to the Brazilian IPCA inflation index or a similar metric.
Clients can cancel at any time through a formal written request to Shosp’s support or official contact channel.
For monthly plans, access remains active until the end of the billing period, and no partial refund is issued.
For long-term prepaid plans (quarterly, semi-annual, annual):
Shosp refunds 50% of the unused balance for the period paid in advance.
The other 50% is retained as an early termination fee for operational and administrative costs.
Some customer complaints indicate difficulty canceling accounts or stopping recurring charges if cancellation requests are not properly submitted through the official channels.
Failure to pay by the due date results in automatic suspension of platform access.
After 30 days of nonpayment, Shosp may terminate the contract and delete all client data stored in the system.
The user may still export data (in .csv format) within these 30 days before deletion.
After confirmed cancellation or termination, Shosp retains client data for 30 days.
After that period, all stored data — including medical records, patient files, and history — are permanently deleted.
This procedure aligns with Brazil’s LGPD (Lei Geral de Proteção de Dados) privacy compliance framework.
Refunds apply only for prepaid plans and are limited to 50% of the remaining value.
Penalties include:
Interest and fines for delayed invoice payments.
Early cancellation penalties (50%) on prepaid subscription balances.
Any disputes are governed by Brazilian law, with the court of Rio de Janeiro (Comarca do Rio de Janeiro) designated as the exclusive venue for legal proceedings.
Public reviews (e.g., on ReclameAqui) document reports of erroneous billing and slow cancellation processes, especially among users who migrated to another medical management provider (such as iClinic).
Shosp software complies with Brazil’s leading clinical and data protection requirements, meeting standards that ensure both regulatory legitimacy and patient data safety. It is recognized as one of the few healthcare management systems in Brazil that fully adheres to the protocols set by CFM (Conselho Federal de Medicina) and SBIS (Sociedade Brasileira de Informática em Saúde)—two of the country’s primary medical and informatics regulatory bodies.
CFM (Federal Council of Medicine) Compliance: Shosp implements the CFM’s telemedicine and electronic medical record guidelines, which regulate legal validity, data integrity, and auditability of clinical documents. This ensures that teleconsultations and digital medical records generated through Shosp hold the same legal recognition as traditional paper records.
SBIS (Brazilian Health Informatics Society) Standards: The platform adheres to the SBIS certification protocol, which defines the technical, ethical, and legal standards for software systems that handle health information. Compliance ensures that Shosp meets strict Brazilian benchmarks for clinical interoperability, confidentiality, and patient data preservation—specifically aligned with SBIS’s electronic health record certification program.
LGPD (Lei Geral de Proteção de Dados / Brazilian General Data Protection Law): Shosp operates under full LGPD compliance, designating clinics as the “data controllers” and Shosp as the “data processor.” It enforces rights to access, correction, and portability, and guarantees encryption and consent mechanisms for patient privacy. This ensures conformity with Articles 6–19 of the LGPD that govern lawful data processing, storage, and security practices.
ANS TISS Standard: In compliance with Agência Nacional de Saúde Suplementar (ANS) Resolution 305, Shosp supports the TISS standard (Troca de Informação em Saúde Suplementar). This standard enables regulatory compliance for electronic claims processing, billing transparency, and insurance data exchange across Brazilian health networks.
ICP‑Brasil Digital Signature Infrastructure: All digital signatures within Shosp are carried out using certificates issued under the ICP‑Brasil (Brazilian Public Key Infrastructure) framework. This ensures authenticity, integrity, and non‑repudiation of clinical documents stored in the cloud, providing legally valid electronic health record transactions.