I'm using my homegrown secure boot + remote attestation solution for physical security of servers containing medical data. Right now it's cobbled from BIOS with TPM support.
Ultimately, secure boot is a good thing. However, the way it's being implemented is far from perfect. By about ten light-years.