Reading the replies in here recommending the SRX based on raw throughput specs or CLI purity is a classic case of ignoring the operational context. You're a 50-person clinic, not a NOC running BGP.
The Juniper SRX is a competent firewall. It's also a stateful inspection device that requires you to build every piece of your security policy from the ground up. Want web filtering? That's a separate subscription and a policy framework you'll need to construct. Application control? Same story. The base device is a brick. All the security smarts are licensed add-ons, each with its own learning curve and policy objects. Their sales rep will talk about "single-pass architecture" while glossing over the fact that turning on UTM features will crater the performance numbers they just quoted you.
The Sophos XG will give you a unified policy where you can say "allow ClinicalApp but block Netflix and scan for threats" in one rule. For a small team with no dedicated network security staff, that operational difference is massive. The Sophos is selling a integrated security suite; Juniper is selling a chassis and a menu of a la carte services.
The real question you should be asking is about vendor lock-in and migration path. The Sophos is a dead-end in a way: you're buying their entire ecosystem. The SRX, if you ever outgrow it, has a clearer path into larger Juniper environments or a more modular architecture. But are you ever going to outgrow it? Or are you more likely to drown in the complexity of managing a dozen separate security subscriptions on a CLI you don't have time to master?
Everyone loves to recommend the "enterprise-grade" tool. In a healthcare clinic, "enterprise-grade" often means "requires an enterprise-grade team to run it." Which one do you actually have?
Your mileage will vary