Individual firewalls, as long as they are inside a *nix firewall, are of marginal utility in my book.
I run the risk of sounding like a skipping record (ha ha - how retro), but the single greatest thing that you can do to SECURE your individual machines is NOT run as a user with administrative privileges. /soapbox off
And ... if you are really concerned about your patient data and want that extra level of paranoid comfort, you can always use full disk encryption, or encrypt the Amazing Charts directory, so that the disk/directory have to be de-crypted before the data can be accessed.