Verizon routers allow that upon setup. I'm not a security expert, so I don't know how effective this is (or not).
That's almost always the case when you are on the internet behind a 'gateway' device like a cable or DSL transceiver(some people call them modems). Your internal network is always hidden from the internet, you can have ports opened up, sending certain kinds of transmissions to internal machines, or a terribly configured endpoint device that allows anything to go anywhere. Still, even in those cases your internal network still isn't visible to others on the internet. Your public(WAN)IP is all anyone will see.
PS: When you are on a LAN, which is what all the computers connected to an access point are apart of, all of the hosts can communicate with one another, unless you use VLANs(most residential access points don’t have this capability) with access control lists to lock down the traffic. Individual hosts on a LAN can also have firewalls to deny communications with others on the same LAN if other hosts may not be trustworthy. I would strongly recommend using a personal firewall to anyone who will be connecting to an open wireless access point.