Verifiable through the issuing bodies. The GCFE and GCFA tiles below specifically tie to eDiscovery admissibility — Rule 702 reliability and KRE 901 authentication — the points most often raised when a Rule 34 production is challenged or a spoliation motion is filed.
Four pieces of eDiscovery / digital evidence work that turn up in nearly every Kentucky engagement. Each maps to a discovery rule or admissibility rule that a judge will scrutinize.
- Legal-hold chain — written chain beginning at custodian identification through hold release; documented dates, actors, and notification acknowledgments so the chain survives an In re: M3 Edge-style spoliation challenge.
- Rule 34 defensible collection memo & Rule 26(f) conference input — written collection protocol, scope, search-term and date-range methodology, and production-format agreement produced for the Rule 26(f) meet-and-confer and attached to the Rule 34 response.
- Forensically-sound ESI imaging — bit-for-bit (forensic) image with SHA-256 verification and write-blocked acquisition; custody, chain, and hash values travel with the production so any tampering is detectable.
- Rule 702 / KRE 702 / Daubert qualification for ESI productions — credential-based admissibility, methodology peer-review pathway, and known-error-rate citation pattern established in every expert report before deposition or trial.
Anonymous, abstracted examples drawn from eDiscovery engagements — these are illustrative, not testimonials, and contain no identifying facts.
Rule 34 production — challenging the producing party’s hash-verification chain
In a commercial dispute where the producing party delivered a Rule 34 production as a network share rather than under chain of custody, defense counsel retained me to evaluate the integrity of the production. The producing party’s counsel had relied on a logical (not physical) collection that had been staged and re-staged by multiple custodians without hash verification between stages. I produced a forensic re-image of the relevant custodian sources with SHA-256 verification, reconstructed a defensible chain of custody, and demonstrated at deposition that several production volumes could not be authenticated as the unaltered contents of the custodians’ systems at the time of collection. The court ordered supplemental production under a verified protocol.
Rule 26(f) conference — narrowing ESI scope around a custodian’s mailbox
In a matter where the opposing party sought an overbroad scope of ESI from a custodian’s mailbox — the entire mailbox, including personal folders — defense counsel retained me to support the Rule 26(f) meet-and-confer. I prepared a written ESI protocol memo proposing a search-term and date-range approach, de-duplication and de-NISTing steps for ingest, and a redaction workflow for privileged material under FRCP 502(d). The opposing party agreed to the narrowed scope at the Rule 26(f) conference, and the court adopted the protocol in its Rule 16 scheduling order, materially reducing the cost and risk of the production.
Related practice-area pillars: Criminal defense digital forensics →Mobile device forensics →Social media forensics →
Read Willie Kerns's expert bio and credentials → Pre-engagement questions? See the attorney FAQ →Get Kentucky Digital Forensics Insights
New articles on digital evidence, eDiscovery, and authentication — written for Kentucky attorneys.
Have a Kentucky matter governed by Rule 34 / Rule 26(f), or an ESI production under attack?
25 years of digital forensics in Kentucky courts — including eDiscovery collection, review-workflow defensibility, and Rule 702 qualification. Free initial consultation for ESI matters.