Final answer:
Business associates and health plans must comply with security measures when handling EPHI.
Step-by-step explanation:
True. Business associates and health plans must comply with security measures when handling Electronic Protected Health Information (EPHI). The Health Insurance Portability and Accountability Act (HIPAA) mandates that covered entities, including healthcare providers and insurance companies, maintain strict confidentiality of patient records and implement safeguards to protect EPHI from unauthorized access. This includes technical, physical, and administrative safeguards such as encryption, access controls, and employee training.